Impact
Docling’s OpenDocument backend uses the xlink:href attribute of a draw:image element as a raw filesystem path when the referenced part is missing from the archive. The implementation lacks scheme validation, directory confinement, and the enable_local_fetch guard used by other backends. An attacker can supply a malicious document that references an arbitrary local file; Pillow then reads the file and embeds its contents in the conversion output, revealing readable files that can be decoded as images and allowing detection of existing paths. The vulnerability enables an attacker to read any files accessible to the process running the backend, compromising confidentiality of local data.
Affected Systems
The affected component is docling-project docling, specifically versions 2.107.0 through 2.120.3 of the backend/open_document module. The issue was resolved in release 2.120.3; earlier versions remain vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. While no EPSS value is currently available, the absence of a KEV listing suggests limited known exploitation. Exploitation requires the attacker to supply a crafted ODF file to a process that runs the backend; thus the attack vector is local (document upload or injection). If the backend runs with elevated privileges or unrestricted filesystem access, the potential damage escalates, as the attacker can read any file the process can access. Mitigating this risk hinges on applying the available patch or ensuring the backend is isolated with minimal file system permissions.
OpenCVE Enrichment
Github GHSA