PatchSiren cyber security CVE debrief
CVE-2026-105748 docling-project CVE debrief
CVE-2026-105748 is a vulnerability in the docling package that allows disclosure of image files readable by the converting process. A crafted JSON file can set a picture's image `uri` to a local file path, which can be read and embedded as base64 in the output when the converted document is exported with embedded images. The vulnerability affects docling and docling-slim packages with versions prior to 2.131.0. Defenders should assess their exposure to potential image file disclosure and prioritize verifying the affected versions and upgrading to version 2.131.0 or later.
- Vendor
- docling-project
- Product
- docling
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for maintaining and securing systems that use the docling package should assess their exposure to potential image file disclosure and prioritize verifying the affected versions and upgrading to version 2.131.0 or later.
Why it matters
CVE-2026-105748 is a vulnerability in the docling package that allows disclosure of image files readable by the converting process. Defenders should prioritize verifying the affected versions and upgrading to version 2.131.0 or later to prevent potential unauthorized access to sensitive files.
- Disclosure of image files readable by the converting process
- Potential unauthorized access to sensitive files
- Need to verify affected versions and upgrade to version 2.131.0 or later
- Possible impact on systems that use the docling package for document conversion
Technical summary
The docling package accepts serialized `DoclingDocument` JSON as an input format, which can contain a crafted JSON file with a local file path set as a picture's image `uri`. When the converted document is exported with embedded images, the referenced file is read and embedded as base64 in the output. This vulnerability affects docling and docling-slim packages with versions prior to 2.131.0. The vulnerability allows disclosure of image files readable by the converting process. Defenders should prioritize verifying the affected versions of docling and docling-slim, and upgrading to version 2.131.0 or later.
Defensive priority
Defenders should prioritize verifying the affected versions of docling and docling-slim, and upgrading to version 2.131.0 or later. They should also assess their exposure to potential image file disclosure and implement compensating controls to prevent unauthorized access to sensitive files.
Recommended defensive actions
- Verify the affected versions of docling and docling-slim
- Upgrade to version 2.131.0 or later
- Assess exposure to potential image file disclosure
- Implement compensating controls to prevent unauthorized access to sensitive files
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is caused by the docling package's acceptance of serialized `DoclingDocument` JSON as an input format, which can contain a crafted JSON file with a local file path set as a picture's image `uri`. The file is then read and embedded as base64 in the output when the converted document is exported with embedded images. The vulnerability affects docling and docling-slim packages with versions prior to 2.131.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105748 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105748
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105748 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105748
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Docling: Crafted DoclingDocument JSON embeds local image files into converted output
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-p944-4xh2-x776.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/security/advisories/GHSA-p944-4xh2-x776
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/pull/4417
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/commit/d4bb776884aba9aa3132f54773f420853cf7afe4
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/docling-project/docling/releases/tag/v2.131.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.