CVE-2026-105750
Received Received - Intake

Path Traversal in Docling via HTMLBackendOptions

Vulnerability report for CVE-2026-105750, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
docling-project docling >= 2.82.0, < 2.118.1
docling-project docling-slim >= 2.92.0, < 2.118.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Docling versions 2.82.0 to 2.118.1. It allows crafted HTML to read local files via file URLs when using HTMLBackendOptions(render_page=True). The issue occurs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce enable_local_fetch or restrict local requests to the source document directory.

Detection Guidance

Detecting this vulnerability requires checking if you are using Docling versions between 2.82.0 and 2.118.1 with HTMLBackendOptions(render_page=True) enabled. Verify installed versions with pip show docling or check your application dependencies. Inspect configurations for HTMLBackendOptions(render_page=True) and ensure enable_local_fetch is set to false.

Impact Analysis

An attacker could embed a local text file in a browser-rendered page image if Playwright is installed. Only filesystem Path inputs are affected; stream inputs and default configurations are not vulnerable.

Compliance Impact

This vulnerability could potentially lead to unauthorized access to local files through crafted HTML, which may violate data protection requirements under GDPR and HIPAA if sensitive documents are exposed. The issue allows local text files to be embedded in rendered pages, risking confidentiality breaches.

Mitigation Strategies

Upgrade Docling to version 2.118.1 or later immediately. If upgrading is not possible, disable HTMLBackendOptions(render_page=True) in your configurations. Ensure enable_local_fetch is set to false to prevent local file access. Review all HTML rendering backends for potential exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105750. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart