CVE-2026-105750: Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(renderpage=True) permits file URLs because HTMLDocumentBackend.getbrowserrequestblockreason does not enforce the enablelocalfetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Doclingto a version that resolves this vulnerability.Fixed in 2.118.1
Event History
Frequently Asked Questions
Which processing workflows are affected?
Affected workflows use Docling versions from 2.82.0 through before 2.118.1 with HTMLBackendOptions(render_page=True), Playwright installed, and an HTML document supplied as a filesystem Path. Stream inputs are not affected because they use an opaque origin.
Are default Docling deployments exposed?
No. The default configuration, command-line interface, docling-serve, and non-rendering backends are not affected.
What is required to expose local file contents?
A crafted path-backed HTML document must be browser-rendered and embed a file URL pointing to a readable local text file. The issue can cause that file's content to appear in the rendered page image.
What can be done before updating?
Avoid browser rendering for untrusted path-backed HTML, use stream inputs where possible, or use a non-rendering backend. Updating to version 2.118.1 resolves the issue.