GHSA-p944-4xh2-x776

Suggest an improvement
Source
https://github.com/advisories/GHSA-p944-4xh2-x776
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p944-4xh2-x776/GHSA-p944-4xh2-x776.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p944-4xh2-x776
Aliases
Published
2026-10-07T20:41:08Z
Modified
2026-10-07T20:45:04Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Docling: Crafted DoclingDocument JSON embeds local image files into converted output
Details

Summary

docling accepts serialized DoclingDocument JSON as an input format (InputFormat.JSON_DOCLING, enabled by default). A crafted JSON file can set a picture's image uri to a local file path. When the converted document is exported with embedded images (ImageRefMode.EMBEDDED, the CLI default for Markdown and HTML), the referenced file is read and embedded as base64 in the output.

Details

docling/backend/json/docling_json_backend.py validates the JSON into a DoclingDocument without checking image references. The file is then read by docling-core:

  • DoclingDocument._with_embedded_pictures opens file:// and plain-path URIs with PIL.
  • ImageRef.pil_image checks allow_image_file_uri for file:// URIs but not for plain Path values. docling's picture enrichment models load images through this property.

Only files that PIL can decode as an image are disclosed. Other files, such as text files or keys, fail to decode and are not embedded. The different error behaviour does reveal whether a path exists.

Impact

Disclosure of image files readable by the converting process (for example other users' uploads or page images in a shared service), and disclosure of whether a local path exists.

Proof of concept

from pathlib import Path
from docling_core.types.doc import DoclingDocument, ImageRef
from docling_core.types.doc.base import Size

doc = DoclingDocument(name="poc")
doc.add_picture(image=ImageRef(mimetype="image/png", dpi=72, size=Size(width=1, height=1),
                               uri=Path("/srv/uploads/other-user/scan.png")))
doc.save_as_json("poc.json")

docling poc.json --to md embeds the referenced PNG as base64 in poc.md.

Patches

Fixed in docling 2.131.0 by #4417. The Docling JSON backend now drops image references that point at local files (paths, file: URIs and any scheme other than data: and http(s)) and logs a warning. Callers that need to load local images from JSON they trust can opt in with DoclingJSONFormatOption(backend_options=DeclarativeBackendOptions(enable_local_fetch=True)); the CLI has no such option.

Code that loads untrusted JSON directly with docling-core (DoclingDocument.load_from_json) and exports it with embedded images is not covered by this fix; that part is tracked in docling-core.

Workarounds

Upgrade to 2.131.0. For older versions:

  • Remove InputFormat.JSON_DOCLING from allowed_formats when converting untrusted input.
  • Export with ImageRefMode.PLACEHOLDER or ImageRefMode.REFERENCED instead of EMBEDDED.
Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-73"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T20:41:08Z",
    "nvd_published_at": "2026-10-05T22:16:57Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / docling

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.16.0
Fixed
2.131.0

Affected versions

2.*
2.16.0
2.17.0
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.23.1
2.24.0
2.25.0
2.25.1
2.25.2
2.26.0
2.27.0
2.28.0
2.28.1
2.28.2
2.28.3
2.28.4
2.29.0
2.30.0
2.31.0
2.31.1
2.31.2
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.36.1
2.37.0
2.38.0
2.38.1
2.39.0
2.40.0
2.41.0
2.42.0
2.42.1
2.42.2
2.43.0
2.44.0
2.45.0
2.46.0
2.47.0
2.47.1
2.48.0
2.49.0
2.50.0
2.51.0
2.52.0
2.53.0
2.54.0
2.55.0
2.55.1
2.56.0
2.56.1
2.57.0
2.58.0
2.59.0
2.60.0
2.60.1
2.61.0
2.61.1
2.61.2
2.62.0
2.63.0
2.64.0
2.64.1
2.65.0
2.66.0
2.67.0
2.68.0
2.69.0
2.69.1
2.70.0
2.71.0
2.72.0
2.73.0
2.73.1
2.74.0
2.75.0
2.76.0
2.77.0
2.78.0
2.79.0
2.80.0
2.81.0
2.82.0
2.83.0
2.84.0
2.85.0
2.86.0
2.87.0
2.88.0
2.89.0
2.90.0
2.91.0
2.92.0
2.93.0
2.94.0
2.95.0
2.96.0
2.96.1
2.97.0
2.98.0
2.99.0
2.100.0
2.101.0
2.102.0
2.102.1
2.102.2
2.103.0
2.104.0
2.105.0
2.106.0
2.107.0
2.108.0
2.109.0
2.110.0
2.111.0
2.112.0
2.113.0
2.114.0
2.115.0
2.116.0
2.117.0
2.118.0
2.118.1
2.119.0
2.120.1
2.120.2
2.120.3
2.121.0
2.122.0
2.123.0
2.123.1
2.124.0
2.125.0
2.126.0
2.127.0
2.128.0
2.129.0
2.130.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p944-4xh2-x776/GHSA-p944-4xh2-x776.json"

PyPI / docling-slim

Package

Name
docling-slim
View open source insights on deps.dev
Purl
pkg:pypi/docling-slim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.92.0
Fixed
2.131.0

Affected versions

2.*
2.92.0
2.93.0
2.94.0
2.95.0
2.96.0
2.96.1
2.97.0
2.98.0
2.99.0
2.100.0
2.101.0
2.102.0
2.102.1
2.102.2
2.103.0
2.104.0
2.105.0
2.106.0
2.107.0
2.108.0
2.109.0
2.110.0
2.111.0
2.112.0
2.113.0
2.114.0
2.115.0
2.116.0
2.117.0
2.118.0
2.118.1
2.119.0
2.120.1
2.120.2
2.120.3
2.121.0
2.122.0
2.123.0
2.123.1
2.124.0
2.125.0
2.126.0
2.127.0
2.128.0
2.129.0
2.130.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p944-4xh2-x776/GHSA-p944-4xh2-x776.json"