Document Processing Tool with Unsafe URI and Path Handling Vulnerability
CVE-2026-47214

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-47214?

The HTML backend of Docling, a document processing tool that integrates with generative AI, exhibits improper input validation prior to version 2.94.0. This vulnerability arises from unsafe handling of URIs and paths, potentially allowing unauthorized access or manipulation of sensitive data within document processing operations. The issue has been addressed and resolved in the release of version 2.94.0, emphasizing the importance of keeping software updated to mitigate risks.

Affected Version(s)

docling < 2.94.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.