Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.
Published: 2026-10-05
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Local data exposure
Action: Apply patch
AI Analysis

Impact

Docling 2.82.0 through 2.118.1 permits browser‑rendered HTML pages to load local file URLs when the `enable_local_fetch` configuration option is not enforced. The vulnerable path‑backed HTML can embed a readable local text file into a browser‑rendered page image if Playwright is installed. This flaw enables an attacker who can influence the HTML input to read arbitrary files from the local filesystem, thus exposing confidential data without exploiting code execution. The weakness corresponds to CWE‑552 and CWE‑863 after failure to enforce a local‑fetch restriction.

Affected Systems

The issue affects the docling-project:docling and docling-project:docling-slim packages in all released versions from 2.82.0 up to 2.118.1. The fixed release is 2.118.1; all earlier or intermediate versions before 2.118.1 remain vulnerable while later releases are considered safe.

Risk and Exploitability

The CVSS score is 5.9, indicating a medium severity flaw that primarily leads to local filesystem disclosure. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to supply crafted HTML that is then rendered by Docling’s HTML backend using Playwright; the vulnerability does not allow arbitrary code execution or privilege escalation. Because the flaw can expose proprietary or sensitive local files, the risk is moderate but non‑negligible for environments that accept untrusted HTML inputs.

Generated by OpenCVE AI on October 5, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the docling or docling-slim package to version 2.118.1 or later, which contains the fix for the enable_local_fetch enforcement.
  • If an upgrade is not immediately possible, disable the HTML browser rendering mode or set enable_local_fetch to false for the affected rendering workflow, and ensure that Playwright is not available to the Docling process.
  • Validate that any HTML input paths originate from trusted sources and do not contain local file URLs before rendering.

Generated by OpenCVE AI on October 5, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.
Title Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Weaknesses CWE-552
CWE-863
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T21:38:28.098Z

Reserved: 2026-10-05T19:11:07.947Z

Link: CVE-2026-105750

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T22:16:58.097

Modified: 2026-10-05T22:16:58.097

Link: CVE-2026-105750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties

  • CWE-863

    Incorrect Authorization