Docling, Incorrect Behavior Order, CVE-2026-105745 (medium) -DC-Oct2026-2868

Listen to this Post

The vulnerability stems from an incorrect order of operations in docling’s plugin initialization logic, where plugin entry points are loaded before any security validation checks are executed. When the application or its command-line interface starts, it invokes pluggy’s loading mechanism to parse available entry-point groups. This action automatically triggers the import of all registered modules on the system under that namespace. Although subsequent checks attempt to filter out modules outside of the permitted namespace and log that they will not be loaded, this validation is performed strictly post-import. As a result, any import-time code included within a third-party or compromised package executes immediately upon startup, completely bypassing the protective intent of restrictions like allow_external_plugins equals false.

DailyCVE Form:

Platform: Docling
Version: 2.131.0
Vulnerability : Incorrect behavior order
Severity: Medium
date: 2026-10-05

Prediction: 2026-10-05

What Undercode Say:

python3 -c "import importlib.metadata; print(list(importlib.metadata.entry_points()))"

Exploit: (Educational Purposes!)

An attacker creates a malicious package registering an entry point under docling’s plugin group containing arbitrary execution logic within its top-level __init__.py. When an administrator runs docling with external plugins disabled, the import-time code executes automatically during startup.

Protection: from this CVE

Upgrade to docling version 2.131.0 or higher where filtering occurs prior to loading. Ensure environments only contain trusted packages.

Impact:

Execution of arbitrary third-party import-time code within the running docling process despite configuration settings blocking external plugins.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top