Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44022

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malicious LaTeX documents with path traversal sequences to read arbitrary files from the file system accessible to the process, include sensitive files in the converted document output, or potentially access configuration files, credentials, or other sensitive data This vulnerability is fixed in 2.91.0.

A flaw was found in Docling, a tool for document processing. The LaTeX backend, responsible for handling commands like \includegraphics, \input, and \include, lacked proper validation for file paths. This vulnerability allows an attacker to craft a malicious LaTeX document containing path traversal sequences. When processed, this could enable the attacker to read arbitrary files from the system, include sensitive files in the converted document output, and potentially access confidential information such as configuration files or credentials.

Отчет

This Moderate impact flaw in Docling's LaTeX backend allows an attacker to read arbitrary files from the system. By crafting a malicious LaTeX document with path traversal sequences, an attacker could exploit this vulnerability when a user processes the document, potentially leading to the disclosure of sensitive information such as configuration files or credentials. This issue primarily affects instances where Docling is used to process untrusted LaTeX content, such as within Red Hat OpenShift AI.

Меры по смягчению последствий

To mitigate this vulnerability, avoid processing untrusted LaTeX documents with Docling. If processing untrusted documents is unavoidable, ensure that Docling operates within a sandboxed environment with strictly limited file system access to prevent unauthorized file reads.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-autorag-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2492379docling: Docling: Information disclosure via path traversal in LaTeX backend

EPSS

Процентиль: 6%
0.00163
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 2 месяцев назад

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malicious LaTeX documents with path traversal sequences to read arbitrary files from the file system accessible to the process, include sensitive files in the converted document output, or potentially access configuration files, credentials, or other sensitive data This vulnerability is fixed in 2.91.0.

CVSS3: 5.5
github
2 месяца назад

Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands

EPSS

Процентиль: 6%
0.00163
Низкий

5.5 Medium

CVSS3