JavaScript Execution Vulnerability in Docling by Docling Project
CVE-2026-44016
8.2HIGH
What is CVE-2026-44016?
The Docling product, which simplifies document processing via a range of formats and integrates with generative AI tools, has a vulnerability in versions between 2.82.0 and less than 2.91.0. When the HTML backend is configured for rendering, an attacker could exploit this to inject malicious HTML. This could result in arbitrary JavaScript code execution and unauthorized network access, potentially leading to server-side request forgery (SSRF) attacks, data theft, or remote code execution. It is crucial for users to upgrade to version 2.91.0, where this issue is resolved.
Affected Version(s)
docling >= 2.82.0, < 2.91.0
