Get real-time updates on Telegram
Verified
Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
CVE-2026-105751 affects docling. Affected range: >= 2.107.0, < 2.120.3. Fixed version: 2.120.3.
- CVE
- CVE-2026-105751
- CWE
- CWE-22
- Product
- docling
- KEV
- no
Affected products
- docling · >= 2.107.0, < 2.120.3 · Fixed version: 2.120.3
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-05 23:09:08.830529+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-05 23:10:51.172112+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-105751.html