Local File Inclusion Vulnerability in Docling by Docling Project
CVE-2026-105751

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105751?

A local file inclusion vulnerability has been identified in Docling, affecting versions from 2.107.0 to 2.120.3. The issue arises from the way the application processes the xlink:href attribute in draw:image elements. When a referenced part is not located in the document archive, the application proceeds to utilize the xlink:href value as a filesystem path without proper security checks. This oversight allows attacker-controlled paths to be read, exposing readable files that can be decoded as images by Pillow. Additionally, the vulnerability could reveal other existing paths based on the attempt to read specified files. This issue has been resolved in version 2.120.3.

Affected Version(s)

docling >= 2.107.0, < 2.120.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.