CyberRota Analysis
AI-GeneratedThe vulnerability affects Docling Core versions 1.5.0 to 2.74.1, allowing for Server-Side Request Forgery (SSRF) attacks due to insufficient restrictions on remote request destinations. This flaw can enable attackers to access local files outside the user-defined cache directory by exploiting untrusted URLs. Organizations using affected versions of Docling should prioritize upgrading to version 2.74.1 to mitigate potential data exposure risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. This issue has been fixed in version 2.74.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)