Time-of-check Time-of-use (TOCTOU) Race Conditiondocling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.
Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition via the HTML backend's remote fetch logic in html_backend.py and image_resource_loader.py, when remote fetching is enabled. An attacker can supply a document containing URLs that resolve to internal or otherwise restricted network addresses (including IPv4 addresses embedded in IPv6 addresses), causing the backend to issue requests to those addresses without validation. Redirects are followed without per-hop address validation, and configured HTMLBackendOptions.headers (which may carry credentials or tokens) are forwarded to cross-origin destinations reached through redirects.
Note: This is only exploitable when enable_remote_fetch=True is explicitly set, as remote fetching is disabled by default. When a proxy is configured through environment variables, requests go through the proxy, which is then responsible for filtering destinations.
How to fix Time-of-check Time-of-use (TOCTOU) Race Condition? Upgrade docling-slim to version 2.132.0 or higher.
| |
Directory Traversaldocling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.
Affected versions of this package are vulnerable to Directory Traversal via the TectonicEngine class in docling/backend/latex/engines/tectonic.py when processing LaTeX input containing TikZ pictures. When the Tectonic engine is used to render TikZ diagrams, it compiles the TikZ body and document preamble without restricting TeX file primitives (\openin, \openout, \input, \include, etc.) or shell escape (\write18), allowing an attacker who controls the LaTeX input to read or write arbitrary files on the host filesystem, or execute arbitrary shell commands. Prior to the fix, TectonicEngine defaulted to allow_shell_escape=True, enabling \write18 shell command execution, and performed no pre-flight check for path traversal or unsafe TeX primitives referencing files outside the rendering directory.
Note: This is only exploitable when the LaTeX backend is explicitly configured to render TikZ pictures with the Tectonic engine (LatexBackendOptions(tikz_engine="tectonic")). The default configuration (tikz_engine=None) is not affected.
How to fix Directory Traversal? Upgrade docling-slim to version 2.132.0 or higher.
| |
Insertion of Sensitive Information Into Sent Datadocling-slim is a Modular version of the Docling package: SDK and CLI for parsing PDF, DOCX, HTML, and more, to a unified document representation for powering downstream workflows such as gen AI applications.
Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the HTML backend's remote fetch logic in html_backend.py when remote fetching is enabled. An attacker who controls a document URL can supply a URL that resolves to an internal or loopback address (including IPv4-mapped IPv6 addresses), cause the backend to follow redirects to arbitrary hosts without re-validating each hop, and leak responses to the attacker. Additionally, configured HTMLBackendOptions.headers (which may contain credentials or tokens) are forwarded to any origin reached during redirects rather than being scoped to the source document's origin.
Note: This is only exploitable when remote fetching is enabled and HTMLBackendOptions.headers are configured; the default configuration is not affected.
How to fix Insertion of Sensitive Information Into Sent Data? Upgrade docling-slim to version 2.132.0 or higher.
| |