Path Traversal Vulnerability in Docling's LaTeX Backend
CVE-2026-44022
5.5MEDIUM
What is CVE-2026-44022?
A path traversal vulnerability exists in Docling's LaTeX backend versions 2.73.0 to 2.91.0, which inadequately validates the paths of commands like \includegraphics, \input, and \include. This defect allows attackers to create malicious LaTeX documents containing path traversal sequences. As a result, attackers can potentially access sensitive files from the host file system, including configuration and credential files, thereby compromising sensitive data. The issue is resolved in version 2.91.0.
Affected Version(s)
docling >= 2.73.0, < 2.91.0
