PT-2026-46122 · Docling · Docling
CVE-2026-44022
·
Published
2026-06-03
·
Updated
2026-06-26
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Docling versions prior to 2.91.0
Description
The LaTeX backend fails to validate path containment when handling the
includegraphics, input, and include commands. This allows attackers to use path traversal sequences, such as ../../../etc/passwd, to read arbitrary files from the file system accessible to the process and include sensitive data, such as configuration files or credentials, in the converted document output.Recommendations
Update to version 2.91.0.
Avoid processing untrusted LaTeX documents.
Run the process in a sandboxed environment with restricted file system access.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docling