{"id":"GHSA-9jxx-vjrv-h2rq","summary":"Docling imports plugin entry points before the allow_external_plugins check","details":"### Summary\n\n`allow_external_plugins=False` (the default, and the CLI default) is meant to restrict docling to its own model plugins. However, docling's plugin factories call pluggy's `load_setuptools_entrypoints()`, which imports every module registered under docling's plugin entry-point group. Only afterwards does docling filter out modules outside the `docling.` namespace. Import-time code in any installed third-party plugin therefore runs even though external plugins are disabled.\n\n### Details\n\nIn `docling/models/factories/base_factory.py`, `load_from_plugins()` loads all entry points first and applies the `allow_external_plugins` check only to the already-imported modules. The CLI creates these factories when it starts, so running `docling` imports every registered plugin module. A log message says the plugin \"will not be loaded\", although its module has already been imported.\n\n### Affected configurations\n\nEnvironments in which a package registering a docling plugin entry point is installed, for example an unvetted or compromised dependency, and which rely on `allow_external_plugins=False` to keep that code from running.\n\n### Impact\n\nExecution of a third-party plugin module's import-time code in the docling process, contrary to the documented behaviour of `allow_external_plugins=False`.\n\n### Patches\n\nFixed in docling 2.131.0 by [#4413](https://github.com/docling-project/docling/pull/4413). Plugin entry points are now filtered by module name before they are loaded, so with `allow_external_plugins=False` third-party plugin modules are no longer imported.\n\n### Workarounds\n\nUpgrade to 2.131.0. For older versions:\n\nOnly install trusted packages in environments that run docling. Check which packages register docling plugin entry points with `importlib.metadata.entry_points()`.","aliases":["CVE-2026-105745"],"modified":"2026-10-07T20:45:04.370096520Z","published":"2026-10-07T20:40:56Z","database_specific":{"cwe_ids":["CWE-696","CWE-829"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-07T20:40:56Z","nvd_published_at":"2026-10-05T22:16:57Z"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105745"},{"type":"WEB","url":"https://github.com/docling-project/docling/pull/4413"},{"type":"WEB","url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c"},{"type":"PACKAGE","url":"https://github.com/docling-project/docling"},{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.27.0"},{"fixed":"2.131.0"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.118.1","2.119.0","2.120.1","2.120.2","2.120.3","2.121.0","2.122.0","2.123.0","2.123.1","2.124.0","2.125.0","2.126.0","2.127.0","2.128.0","2.129.0","2.130.0","2.27.0","2.28.0","2.28.1","2.28.2","2.28.3","2.28.4","2.29.0","2.30.0","2.31.0","2.31.1","2.31.2","2.32.0","2.33.0","2.34.0","2.35.0","2.36.0","2.36.1","2.37.0","2.38.0","2.38.1","2.39.0","2.40.0","2.41.0","2.42.0","2.42.1","2.42.2","2.43.0","2.44.0","2.45.0","2.46.0","2.47.0","2.47.1","2.48.0","2.49.0","2.50.0","2.51.0","2.52.0","2.53.0","2.54.0","2.55.0","2.55.1","2.56.0","2.56.1","2.57.0","2.58.0","2.59.0","2.60.0","2.60.1","2.61.0","2.61.1","2.61.2","2.62.0","2.63.0","2.64.0","2.64.1","2.65.0","2.66.0","2.67.0","2.68.0","2.69.0","2.69.1","2.70.0","2.71.0","2.72.0","2.73.0","2.73.1","2.74.0","2.75.0","2.76.0","2.77.0","2.78.0","2.79.0","2.80.0","2.81.0","2.82.0","2.83.0","2.84.0","2.85.0","2.86.0","2.87.0","2.88.0","2.89.0","2.90.0","2.91.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9jxx-vjrv-h2rq/GHSA-9jxx-vjrv-h2rq.json"}},{"package":{"name":"docling-slim","ecosystem":"PyPI","purl":"pkg:pypi/docling-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.92.0"},{"fixed":"2.131.0"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.118.1","2.119.0","2.120.1","2.120.2","2.120.3","2.121.0","2.122.0","2.123.0","2.123.1","2.124.0","2.125.0","2.126.0","2.127.0","2.128.0","2.129.0","2.130.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9jxx-vjrv-h2rq/GHSA-9jxx-vjrv-h2rq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}