<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Docling-Project - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/docling-project/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 13:13:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/docling-project/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Read, Write, and Execution in Docling via Tectonic Engine</title><link>https://feed.craftedsignal.io/briefs/2026-10-docling-tectonic-rce/</link><pubDate>Thu, 08 Oct 2026 13:13:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-docling-tectonic-rce/</guid><description>The Docling library contains a vulnerability (CVE-2026-105744) allowing arbitrary file read/write and potential command execution when processing untrusted LaTeX input with the Tectonic engine enabled.</description><content:encoded><![CDATA[<p>Docling (versions 2.94.0 through 2.131.x) contains a high-severity vulnerability involving its integration with the Tectonic LaTeX engine. When users configure the <code>LatexBackendOptions</code> with <code>tikz_engine=&quot;tectonic&quot;</code> to process documents containing TikZ diagrams, the library fails to restrict TeX's file primitives. This allows a maliciously crafted LaTeX document to perform arbitrary file reads, writes, and overwrites at locations accessible to the process.</p>
<p>Furthermore, if the <code>tikz_engine_allow_shell_escape</code> option is set to <code>True</code>, the vulnerability can be escalated to arbitrary command execution via the <code>\write18</code> primitive. This threat is particularly significant for applications that process user-submitted documents or automate report generation. Users are strongly advised to upgrade to Docling 2.132.0 or later, which implements input sanitization and restricts Tectonic execution flags. For environments that cannot immediately patch, Docling must be run within a hardened, isolated sandbox (e.g., containerized, read-only filesystem, no host mounts) to mitigate the impact of unauthorized file system operations.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker creates a malicious LaTeX document incorporating TikZ diagrams containing TeX primitives such as <code>\openin</code>, <code>\openout</code>, or <code>\write18</code>.</li>
<li>The attacker submits this document to an application or service that utilizes the Docling library for document parsing.</li>
<li>The target application processes the document with <code>LatexBackendOptions(tikz_engine=&quot;tectonic&quot;)</code> enabled.</li>
<li>Docling writes the malicious LaTeX content into a temporary file for processing by the Tectonic binary.</li>
<li>The Tectonic engine executes the compilation, during which it processes the attacker's embedded primitives, bypassing directory staging restrictions.</li>
<li>If <code>allow_shell_escape</code> is enabled, the <code>\write18</code> primitive triggers the execution of arbitrary shell commands on the host operating system.</li>
<li>The process reads local files or overwrites system configurations, leading to information disclosure or full system compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to read arbitrary files accessible to the Docling process and overwrite sensitive files. In configurations where shell escape is permitted, attackers achieve remote code execution, potentially leading to a full compromise of the host system. This vulnerability affects any service or application utilizing Docling's LaTeX backend processing capabilities.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Docling and Docling-slim to version 2.132.0 or later immediately to apply the patch for CVE-2026-105744.</li>
<li>Audit existing Docling implementations to ensure <code>tikz_engine_allow_shell_escape</code> is set to <code>False</code> by default.</li>
<li>If upgrading is not immediately possible, execute document processing tasks in highly isolated environments (e.g., restricted containers with no network access, read-only filesystems, and no host volume mounts).</li>
<li>Implement monitoring for unexpected subprocess spawning from document parsing services.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>