{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adoclingdocling/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-105744"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["docling (2.94.0 - 2.131.9)","docling-slim (2.94.0 - 2.131.9)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["docling-project"],"content_html":"\u003cp\u003eDocling (versions 2.94.0 through 2.131.x) contains a high-severity vulnerability involving its integration with the Tectonic LaTeX engine. When users configure the \u003ccode\u003eLatexBackendOptions\u003c/code\u003e with \u003ccode\u003etikz_engine=\u0026quot;tectonic\u0026quot;\u003c/code\u003e to process documents containing TikZ diagrams, the library fails to restrict TeX's file primitives. This allows a maliciously crafted LaTeX document to perform arbitrary file reads, writes, and overwrites at locations accessible to the process.\u003c/p\u003e\n\u003cp\u003eFurthermore, if the \u003ccode\u003etikz_engine_allow_shell_escape\u003c/code\u003e option is set to \u003ccode\u003eTrue\u003c/code\u003e, the vulnerability can be escalated to arbitrary command execution via the \u003ccode\u003e\\write18\u003c/code\u003e primitive. This threat is particularly significant for applications that process user-submitted documents or automate report generation. Users are strongly advised to upgrade to Docling 2.132.0 or later, which implements input sanitization and restricts Tectonic execution flags. For environments that cannot immediately patch, Docling must be run within a hardened, isolated sandbox (e.g., containerized, read-only filesystem, no host mounts) to mitigate the impact of unauthorized file system operations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker creates a malicious LaTeX document incorporating TikZ diagrams containing TeX primitives such as \u003ccode\u003e\\openin\u003c/code\u003e, \u003ccode\u003e\\openout\u003c/code\u003e, or \u003ccode\u003e\\write18\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker submits this document to an application or service that utilizes the Docling library for document parsing.\u003c/li\u003e\n\u003cli\u003eThe target application processes the document with \u003ccode\u003eLatexBackendOptions(tikz_engine=\u0026quot;tectonic\u0026quot;)\u003c/code\u003e enabled.\u003c/li\u003e\n\u003cli\u003eDocling writes the malicious LaTeX content into a temporary file for processing by the Tectonic binary.\u003c/li\u003e\n\u003cli\u003eThe Tectonic engine executes the compilation, during which it processes the attacker's embedded primitives, bypassing directory staging restrictions.\u003c/li\u003e\n\u003cli\u003eIf \u003ccode\u003eallow_shell_escape\u003c/code\u003e is enabled, the \u003ccode\u003e\\write18\u003c/code\u003e primitive triggers the execution of arbitrary shell commands on the host operating system.\u003c/li\u003e\n\u003cli\u003eThe process reads local files or overwrites system configurations, leading to information disclosure or full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files accessible to the Docling process and overwrite sensitive files. In configurations where shell escape is permitted, attackers achieve remote code execution, potentially leading to a full compromise of the host system. This vulnerability affects any service or application utilizing Docling's LaTeX backend processing capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Docling and Docling-slim to version 2.132.0 or later immediately to apply the patch for CVE-2026-105744.\u003c/li\u003e\n\u003cli\u003eAudit existing Docling implementations to ensure \u003ccode\u003etikz_engine_allow_shell_escape\u003c/code\u003e is set to \u003ccode\u003eFalse\u003c/code\u003e by default.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, execute document processing tasks in highly isolated environments (e.g., restricted containers with no network access, read-only filesystems, and no host volume mounts).\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unexpected subprocess spawning from document parsing services.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T13:13:30Z","date_published":"2026-10-08T13:13:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-docling-tectonic-rce/","summary":"The Docling library contains a vulnerability (CVE-2026-105744) allowing arbitrary file read/write and potential command execution when processing untrusted LaTeX input with the Tectonic engine enabled.","title":"Arbitrary File Read, Write, and Execution in Docling via Tectonic Engine","url":"https://feed.craftedsignal.io/briefs/2026-10-docling-tectonic-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:docling:docling:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}