OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105744

HIGH · CVSS 7.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Docling versions 2.94.0 to 2.132.0 are vulnerable when using the TikZ engine with untrusted input, allowing attackers to read sensitive files and create or overwrite files on the system. The flaw arises from insufficient restrictions on TeX file primitives, and enabling the tikz_engine_allow_shell_escape option further exposes the system to arbitrary shell command execution. Organizations using affected versions of Docling for document processing, particularly those integrating with untrusted sources, should prioritize upgrading to version 2.132.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105744
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/latex/engines/tectonic.py to compile an untrusted TikZ body and document preamble without restricting TeX file primitives including \openin and \openout. Crafted input can read files available to the converter and create or overwrite writable files, and enabling the tikz_engine_allow_shell_escape option additionally permits shell commands through TeX. The default configuration, which does not enable Tectonic rendering, is not affected. This vulnerability is fixed in 2.132.0.