CVE-2026-44022

Source
https://cve.org/CVERecord?id=CVE-2026-44022
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-44022.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-44022
Aliases
Published
2026-06-24T17:47:25.553Z
Modified
2026-06-27T11:55:46.959906518Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Details

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of \includegraphics, \input, and \include commands lacked path containment validation. Attackers could craft malicious LaTeX documents with path traversal sequences to read arbitrary files from the file system accessible to the process, include sensitive files in the converted document output, or potentially access configuration files, credentials, or other sensitive data This vulnerability is fixed in 2.91.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44022.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/docling-project/docling

Affected ranges

Type
GIT
Repo
https://github.com/docling-project/docling
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Introduced
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.73.0"
        },
        {
            "fixed": "2.91.0"
        }
    ]
}

Affected versions

v2.*
v2.73.0
v2.73.1
v2.74.0
v2.75.0
v2.76.0
v2.77.0
v2.78.0
v2.79.0
v2.80.0
v2.81.0
v2.82.0
v2.83.0
v2.84.0
v2.85.0
v2.86.0
v2.87.0
v2.88.0
v2.89.0
v2.90.0
v2.90.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-44022.json"