Docling, Information Disclosure, CVE-2026-105748 (Medium) -DC-Oct2026-2866

Listen to this Post

CVE-2026-105748 arises from the way docling processes serialized DoclingDocument JSON inputs through the `InputFormat.JSON_DOCLING` backend.
When a user provides a crafted JSON file containing an image URI set to a local system file path or a file URI, the backend fails to perform proper validation on these references.
During the export phase—specifically when utilizing `ImageRefMode.EMBEDDED` which serves as the CLI default for Markdown and HTML formats—internal methods such as `DoclingDocument._with_embedded_pictures` and `ImageRef.pil_image` read the target files via the Pillow library.
Because file paths and file:// URIs are blindly accepted without restriction, the application reads the contents of the targeted local file and embeds its bytes directly into the exported output stream as base64 encoded data.
While image file disclosure is constrained to formats that the Pillow library can decode successfully, other arbitrary files like text files or configuration keys cause decoding errors that fail to embed.
Nevertheless, this differential error behavior and exception handling leak critical intelligence regarding the absolute existence of local paths on the server or service host.
Consequently, unprivileged users or external entities submitting malicious payloads can enumerate server file systems and siphon sensitive image assets belonging to other users or internal service pages.

DailyCVE Form:

Platform: Docling
Version: <2.131.0
Vulnerability : Information Disclosure
Severity: Medium
date: 2026-10-05

Prediction: 2026-10-05

What Undercode Say: Analytics

Bash commands and codes:

docling poc.json --to md
from pathlib import Path
from docling_core.types.doc import DoclingDocument, ImageRef
from docling_core.types.doc.base import Size
doc = DoclingDocument(name="poc")
doc.add_picture(image=ImageRef(mimetype="image/png", dpi=72, size=Size(width=1, height=1),
uri=Path("/srv/uploads/other-user/scan.png")))
doc.save_as_json("poc.json")

How Exploit: (Educational Purposes!)

An attacker creates a malicious JSON payload specifying a targeted local file path or file:// URI within the image reference field of a DoclingDocument object. Once serialized and saved as a JSON file, the payload is fed into the docling conversion utility with default markdown or HTML embedding options enabled. When the utility processes the input, the underlying backend reads the local file from disk and encodes its contents into base64 format within the converted output file, allowing the attacker to retrieve sensitive image contents and map valid system directories.

Protection: from this CVE

Upgrade the docling package to version 2.131.0 or higher where untrusted local file paths, file: URIs, and non-whitelisted URI schemes are automatically dropped and logged. Alternatively, for older versions, remove `InputFormat.JSON_DOCLING` from allowed input formats when handling untrusted data, or configure exports to use `ImageRefMode.PLACEHOLDER` or `ImageRefMode.REFERENCED` instead of EMBEDDED.

Impact:

Successful exploitation results in the unauthorized disclosure of local image files accessible to the conversion process—such as user uploads or service page assets—alongside path existence disclosure via distinct file processing errors.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top