PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105744 docling-project CVE debrief

CVE-2026-105744 is a vulnerability in the docling and docling-slim packages on PyPI. When the LaTeX backend is configured to render TikZ pictures with the Tectonic engine, a crafted `.tex` file can read files the process can read and write files at paths the process can write. If shell-escape is enabled, the document can run shell commands. The vulnerability allows for arbitrary file read/write and command execution. Defenders should assess exposure and prioritize verification and remediation.

Vendor
docling-project
Product
docling
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using the docling and docling-slim packages, particularly those using TikZ rendering with the Tectonic engine, should assess exposure and prioritize verification and remediation. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Defenders should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Why it matters

CVE-2026-105744 is a vulnerability in docling and docling-slim that allows for arbitrary file read/write and command execution when shell-escape is enabled. Defenders should prioritize verifying exposure and restricting use of shell-escape.

  • Arbitrary file read/write can lead to data breaches or corruption
  • Command execution can lead to system compromise or lateral movement
  • Verification of exposure and remediation is necessary to prevent exploitation

Technical summary

The vulnerability is caused by the Tectonic engine not restricting TeX's file primitives when rendering TikZ pictures. This allows for arbitrary file read/write and command execution when shell-escape is enabled. The vulnerability affects docling and docling-slim packages on PyPI. Defenders should prioritize verifying exposure and restricting use of shell-escape. The Tectonic engine writes the picture source into a temporary document and runs the `tectonic` binary on it without any restriction on TeX's file primitives.

Defensive priority

Defenders should prioritize verifying exposure of TikZ rendering with the Tectonic engine and restrict use of shell-escape.

Recommended defensive actions

  • Verify exposure of TikZ rendering with the Tectonic engine
  • Restrict use of shell-escape
  • Update to version 2.132.0 or later
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability allows for arbitrary file read/write and command execution when shell-escape is enabled. Affected versions are from 2.94.0 to 2.132.0 for both docling and docling-slim packages. The Tectonic engine does not restrict TeX's file primitives when rendering TikZ pictures, leading to the vulnerability. Defenders should verify exposure and restrict use of shell-escape.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105744 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105744

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105744 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105744

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Docling has arbitrary file read/write (and command execution when shell-escape is enabled) when

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-x3q2-h9hx-4r4j.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/security/advisories/GHSA-x3q2-h9hx-4r4j

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/pull/4419

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/commit/38b6fa0a465d46fdacbbec333f50fa19c4f6b342

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/releases/tag/v2.132.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.