PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105748 docling-project CVE debrief

CVE-2026-105748 is a vulnerability in the docling package that allows disclosure of image files readable by the converting process. A crafted JSON file can set a picture's image `uri` to a local file path, which can be read and embedded as base64 in the output when the converted document is exported with embedded images. The vulnerability affects docling and docling-slim packages with versions prior to 2.131.0. Defenders should assess their exposure to potential image file disclosure and prioritize verifying the affected versions and upgrading to version 2.131.0 or later.

Vendor
docling-project
Product
docling
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for maintaining and securing systems that use the docling package should assess their exposure to potential image file disclosure and prioritize verifying the affected versions and upgrading to version 2.131.0 or later.

Why it matters

CVE-2026-105748 is a vulnerability in the docling package that allows disclosure of image files readable by the converting process. Defenders should prioritize verifying the affected versions and upgrading to version 2.131.0 or later to prevent potential unauthorized access to sensitive files.

  • Disclosure of image files readable by the converting process
  • Potential unauthorized access to sensitive files
  • Need to verify affected versions and upgrade to version 2.131.0 or later
  • Possible impact on systems that use the docling package for document conversion

Technical summary

The docling package accepts serialized `DoclingDocument` JSON as an input format, which can contain a crafted JSON file with a local file path set as a picture's image `uri`. When the converted document is exported with embedded images, the referenced file is read and embedded as base64 in the output. This vulnerability affects docling and docling-slim packages with versions prior to 2.131.0. The vulnerability allows disclosure of image files readable by the converting process. Defenders should prioritize verifying the affected versions of docling and docling-slim, and upgrading to version 2.131.0 or later.

Defensive priority

Defenders should prioritize verifying the affected versions of docling and docling-slim, and upgrading to version 2.131.0 or later. They should also assess their exposure to potential image file disclosure and implement compensating controls to prevent unauthorized access to sensitive files.

Recommended defensive actions

  • Verify the affected versions of docling and docling-slim
  • Upgrade to version 2.131.0 or later
  • Assess exposure to potential image file disclosure
  • Implement compensating controls to prevent unauthorized access to sensitive files
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is caused by the docling package's acceptance of serialized `DoclingDocument` JSON as an input format, which can contain a crafted JSON file with a local file path set as a picture's image `uri`. The file is then read and embedded as base64 in the output when the converted document is exported with embedded images. The vulnerability affects docling and docling-slim packages with versions prior to 2.131.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105748 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105748

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105748 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105748

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Docling: Crafted DoclingDocument JSON embeds local image files into converted output

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-p944-4xh2-x776.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/security/advisories/GHSA-p944-4xh2-x776

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/pull/4417

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/commit/d4bb776884aba9aa3132f54773f420853cf7afe4

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/docling-project/docling/releases/tag/v2.131.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.