{"id":"GHSA-q43m-vhcp-mhvm","summary":"Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode","details":"### Summary\n\nWhen the HTML backend renders pages in a headless browser (`HTMLBackendOptions(render_page=True)`), the `enable_local_fetch` option is not enforced. A crafted HTML file can embed an arbitrary local file (for example with `\u003ciframe src=\"file:///...\"\u003e`), and that file's contents appear in the page image attached to the returned `DoclingDocument`.\n\n### Details\n\nIn render mode, Playwright requests are filtered by `HTMLDocumentBackend._get_browser_request_block_reason`. In affected versions, this check allowed `file:` URLs unconditionally, before reading any option. As a result:\n\n- `enable_local_fetch=False` did not block local file access, and\n- even with `enable_local_fetch=True`, file access was not limited to the source document's directory, unlike the non-render path (`ImageResourceLoader`), which rejects absolute paths and path traversal.\n\nVersions 2.82.0–2.90.x did no request filtering in render mode at all.\n\nThe browser runs with JavaScript disabled (from 2.91.0), so disclosure is passive: only what Chromium renders visibly inside the page viewport ends up in the page image.\n\nOnly `Path` inputs are affected. They are loaded through a `file://` URL. Stream inputs are loaded with `page.set_content()` into an opaque origin, from which Chromium does not load `file://` subresources.\n\n### Impact\n\nAn attacker who can submit HTML for conversion can read any text file the conversion process can read (for example `.env` files, credential files, or other users' documents on a shared host) by having it rendered into the page image.\n\nOnly applications that meet **all** of these conditions are affected:\n\n- they set `HTMLBackendOptions(render_page=True)` in Python,\n- they have the optional `playwright` dependency installed, and\n- they pass untrusted HTML as a filesystem `Path`.\n\nThe following are **not** affected: the default configuration (`render_page=False`), the `docling` CLI, `docling-serve`, and the EPUB, Markdown, XBRL and email backends.\n\n### Patches\n\nFixed in **2.118.1** (#3948). In render mode, `file:` requests are now blocked unless `enable_local_fetch=True`, and allowed requests are limited to the source document's directory.\n\n### Workarounds\n\nIf you can't upgrade, don't use `render_page=True` on untrusted HTML, or pass the input as a stream instead of a `Path`.\n\n### Credits\n\nReported by @priyankn.","aliases":["CVE-2026-105750"],"modified":"2026-10-06T00:15:12.537258053Z","published":"2026-10-06T00:02:27Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-06T00:02:27Z","nvd_published_at":null,"cwe_ids":["CWE-552","CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/docling-project/docling/security/advisories/GHSA-q43m-vhcp-mhvm"},{"type":"WEB","url":"https://github.com/docling-project/docling/pull/3948"},{"type":"WEB","url":"https://github.com/docling-project/docling/commit/1612b8875b0937447ce3122536fb5360a7102a0a"},{"type":"PACKAGE","url":"https://github.com/docling-project/docling"},{"type":"WEB","url":"https://github.com/docling-project/docling/releases/tag/v2.118.1"}],"affected":[{"package":{"name":"docling","ecosystem":"PyPI","purl":"pkg:pypi/docling"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.82.0"},{"fixed":"2.118.1"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.82.0","2.83.0","2.84.0","2.85.0","2.86.0","2.87.0","2.88.0","2.89.0","2.90.0","2.91.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-q43m-vhcp-mhvm/GHSA-q43m-vhcp-mhvm.json"}},{"package":{"name":"docling-slim","ecosystem":"PyPI","purl":"pkg:pypi/docling-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.92.0"},{"fixed":"2.118.1"}]}],"versions":["2.100.0","2.101.0","2.102.0","2.102.1","2.102.2","2.103.0","2.104.0","2.105.0","2.106.0","2.107.0","2.108.0","2.109.0","2.110.0","2.111.0","2.112.0","2.113.0","2.114.0","2.115.0","2.116.0","2.117.0","2.118.0","2.92.0","2.93.0","2.94.0","2.95.0","2.96.0","2.96.1","2.97.0","2.98.0","2.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-q43m-vhcp-mhvm/GHSA-q43m-vhcp-mhvm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}