GHSA-9jxx-vjrv-h2rq: Medium severity pip/docling-slim vulnerability
Summary
allowexternalplugins=False (the default, and the CLI default) is meant to restrict docling to its own model plugins. However, docling's plugin factories call pluggy's loadsetuptoolsentrypoints(), which imports every module registered under docling's plugin entry-point group. Only afterwards does docling filter out modules outside the docling. namespace. Import-time code in any installed third-party plugin therefore runs even though external plugins are disabled.
Details
In docling/models/factories/basefactory.py, loadfromplugins() loads all entry points first and applies the allowexternalplugins check only to the already-imported modules. The CLI creates these factories when it starts, so running docling imports every registered plugin module. A log message says the plugin "will not be loaded", although its module has already been imported.
Affected configurations
Environments in which a package registering a docling plugin entry point is installed, for example an unvetted or compromised dependency, and which rely on allowexternalplugins=False to keep that code from running.
Impact
Execution of a third-party plugin module's import-time code in the docling process, contrary to the documented behaviour of allowexternalplugins=False.
Patches
Fixed in docling 2.131.0 by #4413. Plugin entry points are now filtered by module name before they are loaded, so with allowexternalplugins=False third-party plugin modules are no longer imported.
Workarounds
Upgrade to 2.131.0. For older versions:
Only install trusted packages in environments that run docling. Check which packages register docling plugin entry points with importlib.metadata.entrypoints().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/docling-slimto a version that resolves this vulnerability.Fixed in 2.131.0 - Upgrade
Upgrade
pip/doclingto a version that resolves this vulnerability.Fixed in 2.131.0 - Upgrade
Upgrade
doclingto a version that resolves this vulnerability.Fixed in 2.131.0 - Compensating control
Only install trusted packages in environments that run docling.