Impact
Untrusted TikZ diagrams supplied to the optional Tectonic engine in Docling can exploit TeX primitives such as \openin and \openout to read or create files on the host system. When the tikz_engine_allow_shell_escape flag is also enabled, shell commands can be executed, providing full remote code execution capabilities. The vulnerability stems from the lack of sandboxing for the TeX compilation process and is a direct result of the Tectonic rendering option being intentionally open to arbitrary TeX code.
Affected Systems
Versions of Docling from 2.94.0 through 2.132.0 that expose the tikz_engine="tectonic" feature are affected. The affected vendors are the docling-project for both the standard and slim distributions. The fix was released in version 2.132.0; earlier releases do not include mitigation for the described flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while no EPSS is reported and the flaw is not listed in the CISA KEV catalog. The flaw is exploitable by supplying a crafted document that uses TikZ, which many document processing workflows ingest. Because the TeX engine can access local files and execute shell commands when the optional flag is enabled, an attacker with control over input can achieve local privilege escalation or compromise the system hosting Docling. The risk is higher in environments where the Docling service is exposed to untrusted users, such as public-facing APIs or shared processing pipelines that accept documents from external sources. The attack does not require additional authentication or elevated privileges beyond those already present in the running Docling process.
OpenCVE Enrichment