Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44022

Опубликовано: 24 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malicious LaTeX documents with path traversal sequences to read arbitrary files from the file system accessible to the process, include sensitive files in the converted document output, or potentially access configuration files, credentials, or other sensitive data This vulnerability is fixed in 2.91.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:docling:docling:*:*:*:*:*:python:*:*
Версия от 2.73.0 (включая) до 2.91.0 (исключая)

EPSS

Процентиль: 6%
0.00163
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
redhat
около 2 месяцев назад

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malicious LaTeX documents with path traversal sequences to read arbitrary files from the file system accessible to the process, include sensitive files in the converted document output, or potentially access configuration files, credentials, or other sensitive data This vulnerability is fixed in 2.91.0.

CVSS3: 5.5
github
2 месяца назад

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

EPSS

Процентиль: 6%
0.00163
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22