Vulnerability  ·  2026-10-07

Docling TikZ/Tectonic command-enabled file read/write + DNS-rebinding SSRF + plugin-import bypass cluster

VulnerabilityMedium impactGlobalCVE-2026-105744
IBM's Docling document-to-structured-data library (used heavily in GenAI/RAG pipelines) had a batch of Oct 5 advisories. The headline (105744): callers opting into the Tectonic engine render untrusted TikZ without restricting TeX file primitives (\openin/\openout), giving arbitrary local file read/write and, with shell-escape enabled, OS command execution. The same batch covers a DNS-rebinding/parser-disagreement SSRF in the image resource loader that reaches internal services (105743), and plugin factories importing every registered entry-point module even when external plugins are disabled — an import-time code-execution vector via a compromised installed package (105745).
Docling is the standard pre-processing layer in many RAG/GenAI doc pipelines, and it routinely ingests untrusted uploaded documents. Attacker-supplied documents (LaTeX/TikZ, ODF, HTML) can read/write files on the conversion host or reach internal/cloud-metadata endpoints, and a poisoned installed package can execute at Docling startup — corrupting the document store feeding downstream models.
Upload a crafted TikZ (.tex) or HTML/ODF document containing TeX file primitives, rebinding hostnames, or file/parser-disagreement payloads; or install a package registering a Docling entry-point that executes on import.
Docling / docling-slim 2.94.0–2.132.0 (CVE-2026-105744 Tectonic; also 2.91.0–2.132.0 SSRF 105743, 2.27.0–2.131.0 plugin import 105745, plus file-URL 105750, xlink:href path 105751, tar members 105747, JSON validation 105748, header forwarding 105742, KServe endpoint 105746)
Upgrade to Docling 2.132.0 (105744/105743) / 2.131.0 (105745); keep remote fetching and Tectonic/shell-escape options disabled unless required; sandbox the document-conversion process.
NVD CVE-2026-105744GitHub advisory GHSA-x3q2-h9hx-4r4jNVD CVE-2026-105743NVD CVE-2026-105745
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →