Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p944-4xh2-x776 | Docling: Crafted DoclingDocument JSON embeds local image files into converted output |
Wed, 07 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docling
Docling docling |
|
| CPEs | cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Docling
Docling docling |
Tue, 06 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 05 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docling-project
Docling-project docling |
|
| Vendors & Products |
Docling-project
Docling-project docling |
Mon, 05 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py validates serialized DoclingDocument input without rejecting picture image references that contain local paths or file URIs. When the document is enriched or exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods can open those references and place readable image bytes in Markdown or HTML output. Disclosure is limited to files Pillow can decode as images, while differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this Docling fix. This issue is fixed in 2.131.0. | |
| Title | Docling: Crafted DoclingDocument JSON embeds local image files into converted output | |
| Weaknesses | CWE-200 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T14:17:25.343Z
Reserved: 2026-10-05T19:11:07.947Z
Link: CVE-2026-105748
Updated: 2026-10-06T14:17:20.726Z
Status : Analyzed
Published: 2026-10-05T22:16:57.793
Modified: 2026-10-07T18:47:00.463
Link: CVE-2026-105748
OpenCVE Enrichment
Updated: 2026-10-05T23:00:19Z
Github GHSA