GHSA-9jxx-vjrv-h2rq: Medium severity pip/docling-slim vulnerability

Published Oct 7, 2026
·
Updated

Summary

allowexternalplugins=False (the default, and the CLI default) is meant to restrict docling to its own model plugins. However, docling's plugin factories call pluggy's loadsetuptoolsentrypoints(), which imports every module registered under docling's plugin entry-point group. Only afterwards does docling filter out modules outside the docling. namespace. Import-time code in any installed third-party plugin therefore runs even though external plugins are disabled.

Details

In docling/models/factories/basefactory.py, loadfromplugins() loads all entry points first and applies the allowexternalplugins check only to the already-imported modules. The CLI creates these factories when it starts, so running docling imports every registered plugin module. A log message says the plugin "will not be loaded", although its module has already been imported.

Affected configurations

Environments in which a package registering a docling plugin entry point is installed, for example an unvetted or compromised dependency, and which rely on allowexternalplugins=False to keep that code from running.

Impact

Execution of a third-party plugin module's import-time code in the docling process, contrary to the documented behaviour of allowexternalplugins=False.

Patches

Fixed in docling 2.131.0 by #4413. Plugin entry points are now filtered by module name before they are loaded, so with allowexternalplugins=False third-party plugin modules are no longer imported.

Workarounds

Upgrade to 2.131.0. For older versions:

Only install trusted packages in environments that run docling. Check which packages register docling plugin entry points with importlib.metadata.entrypoints().

Affected Software

2 affected componentsFixes available
pip/docling-slim>=2.92.0<2.131.0
2.131.0
pip/docling>=2.27.0<2.131.0
2.131.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/docling-slim to a version that resolves this vulnerability.

    Fixed in 2.131.0
  2. Upgrade

    Upgrade pip/docling to a version that resolves this vulnerability.

    Fixed in 2.131.0
  3. Upgrade

    Upgrade docling to a version that resolves this vulnerability.

    Fixed in 2.131.0
  4. Compensating control

    Only install trusted packages in environments that run docling.

Event History

Oct 7, 2026
Advisory Published
via GitHub·08:40 PM
Data Sourced
via GitHub·08:40 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203