๐Ÿ” CVE Alert

CVE-2026-105751

UNKNOWN 0.0

Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.107.0 until 2.120.3, docling/backend/opendocument_backend.py uses the xlink:href attribute value of a draw:image element as a filesystem path when the referenced part is not found in the document archive. The _image_ref_from_odf_image function reads that attacker-controlled path without a scheme check, extraction-directory confinement, or the enable_local_fetch setting used by other backends. Readable files that Pillow can decode as images are embedded in converted output, and other existing paths can be distinguished through the attempted read. This issue is fixed in 2.120.3.

CWE CWE-22
Vendor docling-project
Product docling
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for docling-project docling

Be the first to know when new unknown vulnerabilities affecting docling-project docling are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

docling-project / docling
>= 2.107.0, < 2.120.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/docling-project/docling/security/advisories/GHSA-4xhp-xg4w-8ppm github.com: https://github.com/docling-project/docling/pull/4015 github.com: https://github.com/docling-project/docling/commit/6ee9965adfc364b3696a67c825ec2f0d9cee4311 github.com: https://github.com/docling-project/docling/releases/tag/v2.120.3