Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqxf-v2gg-x3hc

Опубликовано: 22 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage

Impact

A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in docling-core >=2.21.0, <2.48.4 and, specifically only if the application uses pyyaml < 5.4 and invokes docling_core.types.doc.DoclingDocument.load_from_yaml() passing it untrusted YAML data.

Patches

The vulnerability has been patched in docling-core version 2.48.4. The fix mitigates the issue by switching PyYAML deserialization from yaml.FullLoader to yaml.SafeLoader, ensuring that untrusted data cannot trigger code execution.

Workarounds

Users who cannot immediately upgrade docling-core can alternatively ensure that the installed version of PyYAML is 5.4 or greater, which supposedly patches CVE-2020-14343.

References

  • GitHub Issue: #482
  • Upstream Advisory: CVE-2020-14343
  • Fix Release: v2.48.4

Пакеты

Наименование

docling-core

pip
Затронутые версииВерсия исправления

>= 2.21.0, < 2.48.4

2.48.4

EPSS

Процентиль: 34%
0.00138
Низкий

8.1 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
nvd
16 дней назад

Docling Core (or docling-core) is a library that defines core data types and transformations in the document processing application Docling. A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in docling-core starting in version 2.21.0 and prior to version 2.48.4, specifically only if the application uses pyyaml prior to version 5.4 and invokes `docling_core.types.doc.DoclingDocument.load_from_yaml()` passing it untrusted YAML data. The vulnerability has been patched in docling-core version 2.48.4. The fix mitigates the issue by switching `PyYAML` deserialization from `yaml.FullLoader` to `yaml.SafeLoader`, ensuring that untrusted data cannot trigger code execution. Users who cannot immediately upgrade docling-core can alternatively ensure that the installed version of PyYAML is 5.4 or greater.

EPSS

Процентиль: 34%
0.00138
Низкий

8.1 High

CVSS3

Дефекты

CWE-502