Arbitrary File Read, Write, and Execution in Docling via Tectonic Engine
The Docling library contains a vulnerability (CVE-2026-105744) allowing arbitrary file read/write and potential command execution when processing untrusted LaTeX input with the Tectonic engine enabled.
CVE search metadata
CVE search record: CVE-2026-105744. Severity: high. CVSS: 7.5. EPSS: 0.30%. KEV: no. Product: docling (2.94.0 - 2.131.9), docling-slim (2.94.0 - 2.131.9). Brief: Arbitrary File Read, Write, and Execution in Docling via Tectonic Engine. Brief link: https://feed.craftedsignal.io/briefs/2026-10-docling-tectonic-rce/
Docling (versions 2.94.0 through 2.131.x) contains a high-severity vulnerability involving its integration with the Tectonic LaTeX engine. When users configure the LatexBackendOptions with tikz_engine="tectonic" to process documents containing TikZ diagrams, the library fails to restrict TeX's file primitives. This allows a maliciously crafted LaTeX document to perform arbitrary file reads, writes, and overwrites at locations accessible to the process.
Furthermore, if the tikz_engine_allow_shell_escape option is set to True, the vulnerability can be escalated to arbitrary command execution via the \write18 primitive. This threat is particularly significant for applications that process user-submitted documents or automate report generation. Users are strongly advised to upgrade to Docling 2.132.0 or later, which implements input sanitization and restricts Tectonic execution flags. For environments that cannot immediately patch, Docling must be run within a hardened, isolated sandbox (e.g., containerized, read-only filesystem, no host mounts) to mitigate the impact of unauthorized file system operations.
Attack Chain
- The attacker creates a malicious LaTeX document incorporating TikZ diagrams containing TeX primitives such as
\openin,\openout, or\write18. - The attacker submits this document to an application or service that utilizes the Docling library for document parsing.
- The target application processes the document with
LatexBackendOptions(tikz_engine="tectonic")enabled. - Docling writes the malicious LaTeX content into a temporary file for processing by the Tectonic binary.
- The Tectonic engine executes the compilation, during which it processes the attacker's embedded primitives, bypassing directory staging restrictions.
- If
allow_shell_escapeis enabled, the\write18primitive triggers the execution of arbitrary shell commands on the host operating system. - The process reads local files or overwrites system configurations, leading to information disclosure or full system compromise.
Impact
Successful exploitation allows unauthenticated attackers to read arbitrary files accessible to the Docling process and overwrite sensitive files. In configurations where shell escape is permitted, attackers achieve remote code execution, potentially leading to a full compromise of the host system. This vulnerability affects any service or application utilizing Docling's LaTeX backend processing capabilities.
Recommendation
- Upgrade Docling and Docling-slim to version 2.132.0 or later immediately to apply the patch for CVE-2026-105744.
- Audit existing Docling implementations to ensure
tikz_engine_allow_shell_escapeis set toFalseby default. - If upgrading is not immediately possible, execute document processing tasks in highly isolated environments (e.g., restricted containers with no network access, read-only filesystems, and no host volume mounts).
- Implement monitoring for unexpected subprocess spawning from document parsing services.
Immediate actions
Upgrade docling and docling-slim to version 2.132.0 or later.
Mitigations
Disable shell escape in Docling pipeline options and sandbox document processing.
CVE-2026-105744