CVE-2026-105751 with a CVSS score of 6.9 is a vulnerability affecting docling versions Introduced by commit `e2afe381`, "feat: Add OpenDocument backend support and improve ODF in docling where an attacker can read arbitrary local files via draw:image xlink:href in the OpenDocument backend, exploiting the fact that the ODF backend resolves the `xlink:href` attribute as a filesystem path without scheme check or confinement to the extraction directory, allowing an attacker to open an absolute path on the converting host and disclose its contents. Affected versions are >= 2.107.0, < 2.120.3, introduced by commit e2afe381 in v2.107.0, and this flaw can be exploited via a crafted.odt file that triggers the ODF backend to resolve the `xlink:href` attribute as a filesystem path, allowing an attacker to read arbitrary local files.
We recommend you to update Docling to version 2.120.3.[/subscribe_to_unlock_form]
CVE-2026-105751 with a CVSS score of 6.9 is a vulnerability affecting docling versions Introduced by commit `e2afe381`, "feat: Add OpenDocument backend support and improve ODF in docling where an attacker can read arbitrary local files via draw:image xlink:href in the OpenDocument backend, exploiting the fact that the ODF backend resolves the `xlink:href` attribute as a filesystem path without scheme check or confinement to the extraction directory, allowing an attacker to open an absolute path on the converting host and disclose its contents. Affected versions are >= 2.107.0, < 2.120.3, introduced by commit e2afe381 in v2.107.0, and this flaw can be exploited via a crafted.odt file that triggers the ODF backend to resolve the `xlink:href` attribute as a filesystem path, allowing an attacker to read arbitrary local files.
We recommend you to update Docling to version 2.120.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]