CVE-2026-105748
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py validates serialized DoclingDocument input without rejecting picture image references that contain local paths or file URIs. When the document is enriched or exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods can open those references and place readable image bytes in Markdown or HTML output.
Read full descriptionShow less
Disclosure is limited to files Pillow can decode as images, while differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this Docling fix. This issue is fixed in 2.131.0.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.22%
- Percentile among all scored CVEs: 12
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1203Exploitation for Client Executionexecution85 % - Primary impact
T1005Data from Local Systemcollection80 % - Secondary impact
T1552Unsecured Credentialscredential access70 %
UI:R (requiere interacción usuario abriendo documento JSON) → T1203. Lectura de archivos locales a través de referencias de imagen embebidas en DocumentoDocling → T1005. Revelación de existencia de rutas por comportamiento diferencial de Pillow → T1552 (datos sensibles).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-73, CWE-200
References
- https://github.com/docling-project/docling/commit/d4bb776884aba9aa3132f54773f420853cf7afe4
- https://github.com/docling-project/docling/pull/4417
- https://github.com/docling-project/docling/releases/tag/v2.131.0
- https://github.com/docling-project/docling/security/advisories/GHSA-p944-4xh2-x776
- https://github.com/docling-project/docling/security/advisories/GHSA-p944-4xh2-x776
Raw JSON (NVD)
Show
{
"id": "CVE-2026-105748",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-105748",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-10-06T14:16:57.407957Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "docling-project",
"product": "docling",
"versions": [
{
"status": "affected",
"version": ">= 2.16.0, < 2.131.0"
}
]
},
{
"vendor": "docling-project",
"product": "docling-slim",
"versions": [
{
"status": "affected",
"version": ">= 2.16.0, < 2.131.0"
}
]
}
]
}
],
"published": "2026-10-05T22:16:57.793",
"references": [
{
"url": "https://github.com/docling-project/docling/commit/d4bb776884aba9aa3132f54773f420853cf7afe4",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/pull/4417",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/releases/tag/v2.131.0",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/security/advisories/GHSA-p944-4xh2-x776",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/docling-project/docling/security/advisories/GHSA-p944-4xh2-x776",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-73"
},
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py validates serialized DoclingDocument input without rejecting picture image references that contain local paths or file URIs. When the document is enriched or exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods can open those references and place readable image bytes in Markdown or HTML output. Disclosure is limited to files Pillow can decode as images, while differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this Docling fix. This issue is fixed in 2.131.0."
}
],
"lastModified": "2026-10-07T18:47:00.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF1ED8A9-3F7C-487E-84A7-1F1DEAB7000F",
"versionEndExcluding": "2.131.0",
"versionStartIncluding": "2.16.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}