Docling, Arbitrary File Read and Write, CVE-2026-105744 (High) -DC-Oct2026-2875

Listen to this Post

CVE-2026-105744 is a severe security flaw discovered within the Docling document processing library.
It specifically impacts the LaTeX backend when configured to render TikZ pictures via the Tectonic engine.
When processing input documents using LatexBackendOptions(tikz_engine="tectonic"), docling writes the source code into a temporary directory.
It then executes the tectonic binary to compile the document preamble and TikZ body.
The core underlying mechanism of this vulnerability stems from incomplete file dependency resolution.
The staging function `_resolve_local_dependency` only manages files copied into the temporary working directory.
It fails to restrict or monitor what underlying TeX file primitives can open during compilation time.
Consequently, crafted LaTeX inputs can invoke unrestricted TeX primitives to read arbitrary files.
Commands such as \input, \verbatiminput, and `\openin` allow reading files readable by the process.
The contents of these sensitive local files are then typeset directly into the final conversion output image.
Furthermore, output primitives like `\immediate\openout` and `\write` permit creating or overwriting files.
These unauthorized write operations occur outside the temporary directory without needing shell escape enabled.
Tectonic’s built-in `–untrusted` command-line flag fails to block these file manipulation primitives.
Separately, if callers explicitly configure tikz_engine_allow_shell_escape=True, the security risk escalates significantly.
Under this condition, malicious documents can execute arbitrary shell commands directly via \write18.
Only environments opting into Tectonic rendering for untrusted inputs are vulnerable to this flaw.
Default configurations using `tikz_engine=None` do not install Tectonic automatically and remain fully safe.
The vulnerability has been officially mitigated in version 2.132.0 through enhanced validation logic.
This patch enforces stricter default restrictions and inspects source content before compilation.

DailyCVE Form:

Platform: Docling
Version: 2.94.0-2.132.0
Vulnerability: File Primitives
Severity: High
date: October 2026

Prediction: Already Patched

What Undercode Say:

To verify or handle LaTeX conversions safely with docling, check your package version and ensure proper updates:

Check installed docling version
pip show docling
Upgrade docling to the patched release version
pip install --upgrade docling==2.132.0

Python configuration snippet showing safe backend options usage:

from docling.datamodel.pipeline_options import LatexBackendOptions
Safe configuration ensuring tectonic shell escape is disabled and untrusted input is restricted
pipeline_options = LatexBackendOptions(
tikz_engine="tectonic",
tikz_engine_allow_shell_escape=False
)

Exploit: (Educational Purposes!)

\documentclass{}
\usepackage{tikz}
\begin{document}
\begin{tikzpicture}
\immediate\openout15=/tmp/docling-tectonic-poc.txt
\immediate\write15{written by the input document}
\immediate\closeout15
\node {x};
\end{tikzpicture}
\end{document}

When processed with vulnerable configurations, this proof-of-concept payload successfully creates or overwrites `/tmp/docling-tectonic-poc.txt` on the host system without requiring shell escape permissions.

Protection: from this CVE

Upgrade docling to version 2.132.0 or later where TectonicEngine defaults to allow_shell_escape=False.
Ensure Tectonic runs with `–untrusted` and `–only-cached` flags during compilation.

Avoid enabling `tikz_engine_allow_shell_escape=True` when handling untrusted user input.

Run conversions in an isolated OS-level sandbox (such as a container with read-only filesystems and no host mounts) if processing untrusted LaTeX.

Impact:

Disclosure of local system files readable by the running application process.
Creation or overwriting of files writable by the application process on the host.
Potential code execution if attackers can write to startup configuration files.
Direct command execution if shell escape is explicitly enabled via configuration options.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top