JavaScript Execution Vulnerability in Docling by Docling Project
CVE-2026-44016

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-44016?

The Docling product, which simplifies document processing via a range of formats and integrates with generative AI tools, has a vulnerability in versions between 2.82.0 and less than 2.91.0. When the HTML backend is configured for rendering, an attacker could exploit this to inject malicious HTML. This could result in arbitrary JavaScript code execution and unauthorized network access, potentially leading to server-side request forgery (SSRF) attacks, data theft, or remote code execution. It is crucial for users to upgrade to version 2.91.0, where this issue is resolved.

Affected Version(s)

docling >= 2.82.0, < 2.91.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.