CVE-2026-105745: Docling: Plugin entry points are imported before the allow_external_plugins check
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/basefactory.py call loadsetuptoolsentrypoints() before applying the allowexternalplugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Doclingto a version that resolves this vulnerability.Fixed in 2.131.0
Event History
Frequently Asked Questions
Which deployments are exposed to import-time code execution?
Docling versions from 2.27.0 up to, but not including, 2.131.0 are affected when a third-party or compromised installed package registers an entry point in the Docling plugin group. The code can execute when Docling starts.
Does disabling external plugins prevent this issue?
No. In affected versions, Docling imports registered entry-point modules before it applies the allow_external_plugins check. The later filter may report that the plugin was not loaded even though its import-time code has already run.
What version resolves the issue?
Upgrade Docling to version 2.131.0 or later. The issue is fixed in 2.131.0.