{"id":"GHSA-2j5p-7p5m-cvqr","summary":"Docling: Potential Path Traversal via LaTeX \\includegraphics and \\input Commands","details":"### Impact\nThe LaTeX backend's handling of `\\includegraphics`, `\\input`, and `\\include` commands lacked path containment validation. Attackers could craft malicious LaTeX documents with path traversal sequences (e.g., `../../../etc/passwd`) to:\n- Read arbitrary files from the file system accessible to the process\n- Include sensitive files in the converted document output\n- Potentially access configuration files, credentials, or other sensitive data\n\n### Patches\nFixed in version 2.91.0. The fix implements strict path validation using `Path.resolve().is_relative_to()` to ensure all resolved paths remain within the base document directory. Attempts to traverse outside the base directory are logged and blocked.\n\n### Workarounds\nAvoid processing untrusted LaTeX documents. If processing is necessary, run in a sandboxed environment with restricted file system access.\n\n### References\n- Fix release: [v2.91.0](https://github.com/docling-project/docling/releases/tag/v2.91.0)","aliases":["CVE-2026-44022","PYSEC-2026-2145"],"modified":"2026-07-20T21:46:43.181961949Z","published":"2026-06-03T21:14:35Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-03T21:14:35Z","nvd_published_at":"2026-06-24T18:17:17Z","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/security/advisories/GHSA-2j5p-7p5m-cvqr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44022"},{"type":"PACKAGE","url":"https://github.com/docling-project/docling"},{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.91.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/docling/PYSEC-2026-2145.yaml"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.73.0"},{"fixed":"2.91.0"}]}],"versions":["2.73.0","2.73.1","2.74.0","2.75.0","2.76.0","2.77.0","2.78.0","2.79.0","2.80.0","2.81.0","2.82.0","2.83.0","2.84.0","2.85.0","2.86.0","2.87.0","2.88.0","2.89.0","2.90.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2j5p-7p5m-cvqr/GHSA-2j5p-7p5m-cvqr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}