Vendor
The Docling library contains a vulnerability (CVE-2026-105744) allowing arbitrary file read/write and potential command execution when processing untrusted LaTeX input with the Tectonic engine enabled.