{"id":"CVE-2026-105750","aliases":["GHSA-q43m-vhcp-mhvm","PYSEC-2026-4196"],"url":"https://o3.security/vulnerability/CVE-2026-105750","summary":"Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode","details":"### Summary\n\nWhen the HTML backend renders pages in a headless browser (`HTMLBackendOptions(render_page=True)`), the `enable_local_fetch` option is not enforced. A crafted HTML file can embed an arbitrary local file (for example with `<iframe src=\"file:///...\">`), and that file's contents appear in the page image attached to the returned `DoclingDocument`.\n\n### Details\n\nIn render mode, Playwright requests are filtered by `HTMLDocumentBackend._get_browser_request_block_reason`. In affected versions, this check allowed `file:` URLs unconditionally, before reading any option. As a result:\n\n- `enable_local_fetch=False` did not block local file access, and\n- even with `enable_local_fetch=True`, file access was not limited to the source document's directory, unlike the non-render path (`ImageResourceLoader`), which rejects absolute paths and path traversal.\n\nVersions 2.82.0–2.90.x did no request filtering in render mode at all.\n\nThe browser runs with JavaScript disabled (from 2.91.0), so disclosure is passive: only what Chromium renders visibly inside the page viewport ends up in the page image.\n\nOnly `Path` inputs are affected. They are loaded through a `file://` URL. Stream inputs are loaded with `page.set_content()` into an opaque origin, from which Chromium does not load `file://` subresources.\n\n### Impact\n\nAn attacker who can submit HTML for conversion can read any text file the conversion process can read (for example `.env` files, credential files, or other users' documents on a shared host) by having it rendered into the page image.\n\nOnly applications that meet **all** of these conditions are affected:\n\n- they set `HTMLBackendOptions(render_page=True)` in Python,\n- they have the optional `playwright` dependency installed, and\n- they pass untrusted HTML as a filesystem `Path`.\n\nThe following are **not** affected: the default configuration (`render_page=False`), the `docling` CLI, `docling-serve`, and the EPUB, Markdown, XBRL and email backends.\n\n### Patches\n\nFixed in **2.118.1** (#3948). In render mode, `file:` requests are now blocked unless `enable_local_fetch=True`, and allowed requests are limited to the source document's directory.\n\n### Workarounds\n\nIf you can't upgrade, don't use `render_page=True` on untrusted HTML, or pass the input as a stream instead of a `Path`.\n\n### Credits\n\nReported by @priyankn.","published":"2026-10-05T21:38:28.098Z","modified":"2026-10-08T10:10:55.286174577Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"docling","fixedVersion":"2.118.1"},{"ecosystem":"PyPI","name":"docling-slim","fixedVersion":"2.118.1"}],"fix":{"url":"https://github.com/docling-project/docling/commit/1612b8875b0937447ce3122536fb5360a7102a0a","label":"docling-project/docling@1612b88"},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.118.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105750.json"},{"type":"ADVISORY","url":"https://github.com/docling-project/docling/security/advisories/GHSA-q43m-vhcp-mhvm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105750"},{"type":"FIX","url":"https://github.com/docling-project/docling/commit/1612b8875b0937447ce3122536fb5360a7102a0a"},{"type":"FIX","url":"https://github.com/docling-project/docling/pull/3948"},{"type":"PACKAGE","url":"https://github.com/docling-project/docling"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-08T10:10:55.286174577Z"}}