Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.107.0 until 2.120.3, docling/backend/opendocument_backend.py uses the xlink:href attribute value of a draw:image element as a filesystem path when the referenced part is not found in the document archive. The _image_ref_from_odf_image function reads that attacker-controlled path without a scheme check, extraction-directory confinement, or the enable_local_fetch setting used by other backends. Readable files that Pillow can decode as images are embedded in converted output, and other existing paths can be distinguished through the attempted read. This issue is fixed in 2.120.3.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Local File Read
Action: Patch
AI Analysis

Impact

Docling’s OpenDocument backend uses the xlink:href attribute of a draw:image element as a raw filesystem path when the referenced part is missing from the archive. The implementation lacks scheme validation, directory confinement, and the enable_local_fetch guard used by other backends. An attacker can supply a malicious document that references an arbitrary local file; Pillow then reads the file and embeds its contents in the conversion output, revealing readable files that can be decoded as images and allowing detection of existing paths. The vulnerability enables an attacker to read any files accessible to the process running the backend, compromising confidentiality of local data.

Affected Systems

The affected component is docling-project docling, specifically versions 2.107.0 through 2.120.3 of the backend/open_document module. The issue was resolved in release 2.120.3; earlier versions remain vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. While no EPSS value is currently available, the absence of a KEV listing suggests limited known exploitation. Exploitation requires the attacker to supply a crafted ODF file to a process that runs the backend; thus the attack vector is local (document upload or injection). If the backend runs with elevated privileges or unrestricted filesystem access, the potential damage escalates, as the attacker can read any file the process can access. Mitigating this risk hinges on applying the available patch or ensuring the backend is isolated with minimal file system permissions.

Generated by OpenCVE AI on October 5, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade docling to version 2.120.3 or later
  • Run the docling backend in an isolated environment with restricted filesystem access
  • Verify that the backend process has the least privilege necessary to perform document conversion

Generated by OpenCVE AI on October 5, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4xhp-xg4w-8ppm Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
History

Mon, 05 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Docling-project
Docling-project docling
Vendors & Products Docling-project
Docling-project docling

Mon, 05 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.107.0 until 2.120.3, docling/backend/opendocument_backend.py uses the xlink:href attribute value of a draw:image element as a filesystem path when the referenced part is not found in the document archive. The _image_ref_from_odf_image function reads that attacker-controlled path without a scheme check, extraction-directory confinement, or the enable_local_fetch setting used by other backends. Readable files that Pillow can decode as images are embedded in converted output, and other existing paths can be distinguished through the attempted read. This issue is fixed in 2.120.3.
Title Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Docling-project Docling
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T21:40:45.997Z

Reserved: 2026-10-05T19:11:07.947Z

Link: CVE-2026-105751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T22:16:58.253

Modified: 2026-10-05T22:16:58.253

Link: CVE-2026-105751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')