« Volver al listado

CVE-2026-105750

Estado: AnalizadaAlta (7.5)—

Docling simplifica el procesamiento de documentos analizando formatos diversos y proporcionando integraciones con el ecosistema de IA generativa. Desde la 2.82.0 hasta la 2.118.1, HTMLBackendOptions(render_page=True) permite URL de tipo file porque HTMLDocumentBackend._get_browser_request_block_reason no aplica el ajuste enable_local_fetch ni confina las solicitudes locales al directorio del documento de origen. Un HTML manipulado basado en una ruta puede incrustar un archivo de texto local legible en una imagen de página renderizada por el navegador cuando Playwright está instalado.

Leer descripción completaMostrar menos

Solo se ven afectadas las entradas Path del sistema de archivos, porque las entradas de flujo usan un origen opaco, y la configuración predeterminada, la interfaz de línea de comandos, docling-serve y los backends que no renderizan no se ven afectados. Este problema se ha corregido en la 2.118.1.

Traducción automática del texto original de NVD (en inglés).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Aplicación expuesta en red (AV:N, AC:H) permite leer archivos locales mediante URLs de archivo en HTML renderizado; CWE-552 (permisos inadecuados) y acceso a datos sensibles sin autenticación requerida.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-105750",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-105750",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-10-06T18:17:20.609974Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "docling-project",
          "product": "docling",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.82.0, < 2.118.1"
            }
          ]
        },
        {
          "vendor": "docling-project",
          "product": "docling-slim",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.92.0, < 2.118.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-10-05T22:16:58.097",
  "references": [
    {
      "url": "https://github.com/docling-project/docling/commit/1612b8875b0937447ce3122536fb5360a7102a0a",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/docling-project/docling/pull/3948",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/docling-project/docling/releases/tag/v2.118.1",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/docling-project/docling/security/advisories/GHSA-q43m-vhcp-mhvm",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-552"
        },
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1."
    }
  ],
  "lastModified": "2026-10-07T17:52:51.153",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C5BACD1-2992-465D-93E2-1C62FE28279D",
              "versionEndExcluding": "2.118.1",
              "versionStartIncluding": "2.82.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}