{"id":"CVE-2026-105750","summary":"Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode","details":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.","aliases":["GHSA-q43m-vhcp-mhvm"],"modified":"2026-10-07T10:30:28.453844766Z","published":"2026-10-05T21:38:28.098Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-552","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105750.json"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.118.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105750.json"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-q43m-vhcp-mhvm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105750"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/1612b8875b0937447ce3122536fb5360a7102a0a"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/3948"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docling-project/docling","events":[{"introduced":"d355af6c59d9c0b5a2a26f1bed481e1882a9512a"},{"introduced":"80f81b2799112d66a59b4a292cad3a86d41d06ad"},{"fixed":"72bb55bc765afcc01f60391b1f23978583e08fa4"},{"fixed":"72bb55bc765afcc01f60391b1f23978583e08fa4"},{"fixed":"1612b8875b0937447ce3122536fb5360a7102a0a"}],"database_specific":{"extracted_events":[{"introduced":"2.82.0"},{"fixed":"2.118.1"},{"introduced":"2.92.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.118.0","v2.117.0","v2.116.0","v2.115.0","v2.114.0","v2.113.0","v2.112.0","v2.111.0","v2.110.0","v2.109.0","v2.108.0","v2.107.0","v2.106.0","v2.105.0","v2.104.0","v2.103.0","v2.102.2","v2.102.1","v2.102.0","v2.101.0","v2.100.0","v2.99.0","v2.98.0","v2.97.0","v2.96.1","v2.96.0","v2.95.0","v2.94.0","v2.93.0","v2.92.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105750.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}