Impact
Docling 2.82.0 through 2.118.1 permits browser‑rendered HTML pages to load local file URLs when the `enable_local_fetch` configuration option is not enforced. The vulnerable path‑backed HTML can embed a readable local text file into a browser‑rendered page image if Playwright is installed. This flaw enables an attacker who can influence the HTML input to read arbitrary files from the local filesystem, thus exposing confidential data without exploiting code execution. The weakness corresponds to CWE‑552 and CWE‑863 after failure to enforce a local‑fetch restriction.
Affected Systems
The issue affects the docling-project:docling and docling-project:docling-slim packages in all released versions from 2.82.0 up to 2.118.1. The fixed release is 2.118.1; all earlier or intermediate versions before 2.118.1 remain vulnerable while later releases are considered safe.
Risk and Exploitability
The CVSS score is 5.9, indicating a medium severity flaw that primarily leads to local filesystem disclosure. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to supply crafted HTML that is then rendered by Docling’s HTML backend using Playwright; the vulnerability does not allow arbitrary code execution or privilege escalation. Because the flaw can expose proprietary or sensitive local files, the risk is moderate but non‑negligible for environments that accept untrusted HTML inputs.
OpenCVE Enrichment