{"id":"CVE-2026-105745","aliases":["GHSA-9jxx-vjrv-h2rq","PYSEC-2026-4192"],"url":"https://o3.security/vulnerability/CVE-2026-105745","summary":"Docling: Plugin entry points are imported before the allow_external_plugins check","details":"### Summary\n\n`allow_external_plugins=False` (the default, and the CLI default) is meant to restrict docling to its own model plugins. However, docling's plugin factories call pluggy's `load_setuptools_entrypoints()`, which imports every module registered under docling's plugin entry-point group. Only afterwards does docling filter out modules outside the `docling.` namespace. Import-time code in any installed third-party plugin therefore runs even though external plugins are disabled.\n\n### Details\n\nIn `docling/models/factories/base_factory.py`, `load_from_plugins()` loads all entry points first and applies the `allow_external_plugins` check only to the already-imported modules. The CLI creates these factories when it starts, so running `docling` imports every registered plugin module. A log message says the plugin \"will not be loaded\", although its module has already been imported.\n\n### Affected configurations\n\nEnvironments in which a package registering a docling plugin entry point is installed, for example an unvetted or compromised dependency, and which rely on `allow_external_plugins=False` to keep that code from running.\n\n### Impact\n\nExecution of a third-party plugin module's import-time code in the docling process, contrary to the documented behaviour of `allow_external_plugins=False`.\n\n### Patches\n\nFixed in docling 2.131.0 by [#4413](https://github.com/docling-project/docling/pull/4413). Plugin entry points are now filtered by module name before they are loaded, so with `allow_external_plugins=False` third-party plugin modules are no longer imported.\n\n### Workarounds\n\nUpgrade to 2.131.0. For older versions:\n\nOnly install trusted packages in environments that run docling. Check which packages register docling plugin entry points with `importlib.metadata.entry_points()`.","published":"2026-10-05T21:29:23.561Z","modified":"2026-10-08T10:10:34.336330914Z","cvss":{"score":6.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"docling","fixedVersion":"2.131.0"},{"ecosystem":"PyPI","name":"docling-slim","fixedVersion":"2.131.0"}],"fix":{"url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c","label":"docling-project/docling@0f443b3"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.131.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105745.json"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-9jxx-vjrv-h2rq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105745"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/0f443b3786e98688a2da3b7c8f56fe5e46af876c"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/4413"},{"type":"PACKAGE","url":"https://github.com/docling-project/docling"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-08T10:10:34.336330914Z"}}