docling-slim@2.123.0

Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

  • latest version

    2.135.0

  • latest non vulnerable version

  • first published

    5 months ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the docling-slim package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    External Control of File Name or Path

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to External Control of File Name or Path via the DoclingJSONBackend when processing a DoclingDocument JSON input containing ImageRef fields with local filesystem paths or file:// URIs. An attacker who can supply a malicious JSON document can cause the converter to open arbitrary local files on the host, which are then read by enrichment models or embedded-image export stages, exposing their contents.

    Note: This is only exploitable when the application accepts InputFormat.JSON_DOCLING input, which is enabled by default.

    How to fix External Control of File Name or Path?

    Upgrade docling-slim to version 2.131.0 or higher.

    [2.92.0,2.131.0)
    • M
    Improper Handling of Highly Compressed Data (Data Amplification)

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the METS-GBS backend's archive processing in docling/backend/mets_gbs_backend.py, where max_member_count is enforced only after the full member list has been built by TarFile.getmembers(). An attacker can supply a TAR archive containing an excessive number of members, causing the process to read all headers before the limit is applied, leading to unbounded resource consumption and a crash.

    How to fix Improper Handling of Highly Compressed Data (Data Amplification)?

    Upgrade docling-slim to version 2.131.0 or higher.

    [2.92.0,2.131.0)
    • M
    Time-of-check Time-of-use (TOCTOU) Race Condition

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition via the HTML backend's remote fetch logic in html_backend.py and image_resource_loader.py, when remote fetching is enabled. An attacker can supply a document containing URLs that resolve to internal or otherwise restricted network addresses (including IPv4 addresses embedded in IPv6 addresses), causing the backend to issue requests to those addresses without validation. Redirects are followed without per-hop address validation, and configured HTMLBackendOptions.headers (which may carry credentials or tokens) are forwarded to cross-origin destinations reached through redirects.

    Note: This is only exploitable when enable_remote_fetch=True is explicitly set, as remote fetching is disabled by default. When a proxy is configured through environment variables, requests go through the proxy, which is then responsible for filtering destinations.

    How to fix Time-of-check Time-of-use (TOCTOU) Race Condition?

    Upgrade docling-slim to version 2.132.0 or higher.

    [,2.132.0)
    • M
    Incorrect Behavior Order

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Incorrect Behavior Order via load_from_plugins() in docling/models/factories/base_factory.py, which previously called pluggy's load_setuptools_entrypoints() to import all modules registered under the docling entry-point group before checking whether they belonged to the docling namespace. An attacker who can register a malicious third-party package under the docling entry-point group on the target system can cause that package's module to be imported and its code executed, even when allow_external_plugins=False is configured. The namespace check ran after import, meaning the guard was ineffective at preventing code execution from untrusted plugins.

    How to fix Incorrect Behavior Order?

    Upgrade docling-slim to version 2.131.0 or higher.

    [2.92.0,2.131.0)
    • H
    Directory Traversal

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Directory Traversal via the TectonicEngine class in docling/backend/latex/engines/tectonic.py when processing LaTeX input containing TikZ pictures. When the Tectonic engine is used to render TikZ diagrams, it compiles the TikZ body and document preamble without restricting TeX file primitives (\openin, \openout, \input, \include, etc.) or shell escape (\write18), allowing an attacker who controls the LaTeX input to read or write arbitrary files on the host filesystem, or execute arbitrary shell commands. Prior to the fix, TectonicEngine defaulted to allow_shell_escape=True, enabling \write18 shell command execution, and performed no pre-flight check for path traversal or unsafe TeX primitives referencing files outside the rendering directory.

    Note: This is only exploitable when the LaTeX backend is explicitly configured to render TikZ pictures with the Tectonic engine (LatexBackendOptions(tikz_engine="tectonic")). The default configuration (tikz_engine=None) is not affected.

    How to fix Directory Traversal?

    Upgrade docling-slim to version 2.132.0 or higher.

    [2.94.0,2.132.0)
    • M
    Insertion of Sensitive Information Into Sent Data

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the HTML backend's remote fetch logic in html_backend.py when remote fetching is enabled. An attacker who controls a document URL can supply a URL that resolves to an internal or loopback address (including IPv4-mapped IPv6 addresses), cause the backend to follow redirects to arbitrary hosts without re-validating each hop, and leak responses to the attacker. Additionally, configured HTMLBackendOptions.headers (which may contain credentials or tokens) are forwarded to any origin reached during redirects rather than being scoped to the source document's origin.

    Note: This is only exploitable when remote fetching is enabled and HTMLBackendOptions.headers are configured; the default configuration is not affected.

    How to fix Insertion of Sensitive Information Into Sent Data?

    Upgrade docling-slim to version 2.132.0 or higher.

    [2.95.0,2.132.0)
    • H
    Denial of Service (DoS)

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Denial of Service (DoS) via oversized rowspan/colspan values in table cells processed by the HTML, JATS, BoxNote, and OpenDocument backends. An attacker can supply a document containing table cells that declare span values far larger than the actual table dimensions, causing the grid allocation and fill loops to be sized from the declared span rather than from the real table, resulting in unbounded memory and CPU consumption that crashes the process.

    How to fix Denial of Service (DoS)?

    Upgrade docling-slim to version 2.131.0 or higher.

    [2.92.0,2.131.0)
    • L
    Exposure of Resource to Wrong Sphere

    docling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.

    Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere via the KserveV2OcrModel class in docling/models/stages/ocr/kserve_v2_ocr_model.py, which contacts a remote KServe v2 inference server without checking the enable_remote_services flag. Unlike all other remote engines in the pipeline, this engine unconditionally establishes an outbound connection to the configured inference server, bypassing the authorization gate that is meant to require explicit user opt-in before any remote service contact occurs. An attacker or misconfigured deployment can cause the application to exfiltrate page-crop image data to an unintended remote endpoint.

    Note: This is only exploitable when the KServe v2 OCR engine (KserveV2OcrOptions) is selected as the OCR backend.

    How to fix Exposure of Resource to Wrong Sphere?

    Upgrade docling-slim to version 2.131.0 or higher.

    [2.92.0,2.131.0)