What happened
IBM's Docling document-to-structured-data library (used heavily in GenAI/RAG pipelines) had a batch of Oct 5 advisories. The headline (105744): callers opting into the Tectonic engine render untrusted TikZ without restricting TeX file primitives (\openin/\openout), giving arbitrary local file read/write and, with shell-escape enabled, OS command execution. The same batch covers a DNS-rebinding/parser-disagreement SSRF in the image resource loader that reaches internal services (105743), and plugin factories importing every registered entry-point module even when external plugins are disabled — an import-time code-execution vector via a compromised installed package (105745).
Why it matters
Docling is the standard pre-processing layer in many RAG/GenAI doc pipelines, and it routinely ingests untrusted uploaded documents. Attacker-supplied documents (LaTeX/TikZ, ODF, HTML) can read/write files on the conversion host or reach internal/cloud-metadata endpoints, and a poisoned installed package can execute at Docling startup — corrupting the document store feeding downstream models.
Attack vector
Upload a crafted TikZ (.tex) or HTML/ODF document containing TeX file primitives, rebinding hostnames, or file/parser-disagreement payloads; or install a package registering a Docling entry-point that executes on import.
Affected systems
Docling / docling-slim 2.94.0–2.132.0 (CVE-2026-105744 Tectonic; also 2.91.0–2.132.0 SSRF 105743, 2.27.0–2.131.0 plugin import 105745, plus file-URL 105750, xlink:href path 105751, tar members 105747, JSON validation 105748, header forwarding 105742, KServe endpoint 105746)
Mitigation
Upgrade to Docling 2.132.0 (105744/105743) / 2.131.0 (105745); keep remote fetching and Tectonic/shell-escape options disabled unless required; sandbox the document-conversion process.