Docling, Local File Fetch Bypass, CVE-2026-105750 (Medium) -DC-Oct2026-2742

Listen to this Post

Docling is a document processing library that parses diverse formats and provides integrations with generative AI ecosystems. The vulnerability exists in the HTML backend when the `render_page=True` option is enabled within HTMLBackendOptions. In this mode, Docling uses Playwright to render HTML pages in a headless browser. The `_get_browser_request_block_reason` method is responsible for filtering network requests, including `file:` URLs. In affected versions, this method allowed `file:` URLs unconditionally, before evaluating the `enable_local_fetch` option. Consequently, setting `enable_local_fetch=False` did not block local file access. Even when `enable_local_fetch=True` was set, file access was not restricted to the source document’s directory, unlike the non-render path which uses `ImageResourceLoader` and rejects absolute paths and path traversal. Versions 2.82.0 through 2.90.x performed no request filtering at all in render mode. From version 2.91.0 onward, JavaScript was disabled in the browser, making the disclosure passive: only content visibly rendered inside the page viewport appears in the generated page image. An attacker can craft an HTML file with an `