Impact
Docling’s plugin factory loads setuptools entry points before respecting the allow_external_plugins setting, causing all registered modules in the Docling entry‑point group to be imported even when external plugins are supposedly disabled. A malicious or compromised third‑party package can thus inject code that runs at application startup, leading to local or remote code execution depending on how Docling is deployed. The flaw is a consequence of improper input validation and authorisation, as reflected by the associated CWE identifiers.
Affected Systems
The vulnerability affects the Docling project’s docling and docling-slim packages for all releases from version 2.27.0 up through 2.131.0. Upgrading past 2.131.0 removes the issue, as the plugin import logic has been corrected.
Risk and Exploitability
The CVSS v3 score is 6.7, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to introduce a bad package into the environment where Docling runs; the attack vector is local deployment and potentially remote if Docling is executed as a service in a hostile environment. The flaw’s existence in the plugin loader gives an attacker a reliable path to code execution, aligning with CWE‑696 (Improper Control of Generation of Code) and CWE‑829 (Improper Restriction of Operations within the Code Execution Context).
OpenCVE Enrichment