PatchSiren cyber security CVE debrief
CVE-2026-105744 docling-project CVE debrief
CVE-2026-105744 is a vulnerability in the docling and docling-slim packages on PyPI. When the LaTeX backend is configured to render TikZ pictures with the Tectonic engine, a crafted `.tex` file can read files the process can read and write files at paths the process can write. If shell-escape is enabled, the document can run shell commands. The vulnerability allows for arbitrary file read/write and command execution. Defenders should assess exposure and prioritize verification and remediation.
- Vendor
- docling-project
- Product
- docling
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for systems using the docling and docling-slim packages, particularly those using TikZ rendering with the Tectonic engine, should assess exposure and prioritize verification and remediation. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Defenders should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Why it matters
CVE-2026-105744 is a vulnerability in docling and docling-slim that allows for arbitrary file read/write and command execution when shell-escape is enabled. Defenders should prioritize verifying exposure and restricting use of shell-escape.
- Arbitrary file read/write can lead to data breaches or corruption
- Command execution can lead to system compromise or lateral movement
- Verification of exposure and remediation is necessary to prevent exploitation
Technical summary
The vulnerability is caused by the Tectonic engine not restricting TeX's file primitives when rendering TikZ pictures. This allows for arbitrary file read/write and command execution when shell-escape is enabled. The vulnerability affects docling and docling-slim packages on PyPI. Defenders should prioritize verifying exposure and restricting use of shell-escape. The Tectonic engine writes the picture source into a temporary document and runs the `tectonic` binary on it without any restriction on TeX's file primitives.
Defensive priority
Defenders should prioritize verifying exposure of TikZ rendering with the Tectonic engine and restrict use of shell-escape.
Recommended defensive actions
- Verify exposure of TikZ rendering with the Tectonic engine
- Restrict use of shell-escape
- Update to version 2.132.0 or later
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability allows for arbitrary file read/write and command execution when shell-escape is enabled. Affected versions are from 2.94.0 to 2.132.0 for both docling and docling-slim packages. The Tectonic engine does not restrict TeX's file primitives when rendering TikZ pictures, leading to the vulnerability. Defenders should verify exposure and restrict use of shell-escape.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105744 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105744
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105744 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105744
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Docling has arbitrary file read/write (and command execution when shell-escape is enabled) when
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-x3q2-h9hx-4r4j.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/security/advisories/GHSA-x3q2-h9hx-4r4j
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/pull/4419
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/commit/38b6fa0a465d46fdacbbec333f50fa19c4f6b342
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/releases/tag/v2.132.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.