Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-9jxx-vjrv-h2rq

MediumCVSS 6.7 / 10
Published Oct 7, 2026·Last modified Oct 7, 2026
Affected Components(2)
PyPI logodocling
2.27.0 – 2.131.0
PyPI logodocling-slim
2.92.0 – 2.131.0
Description

Summary

allow_external_plugins=False (the default, and the CLI default) is meant to restrict docling to its own model plugins. However, docling's plugin factories call pluggy's load_setuptools_entrypoints(), which imports every module registered under docling's plugin entry-point group. Only afterwards does docling filter out modules outside the docling. namespace. Import-time code in any installed third-party plugin therefore runs even though external plugins are disabled.

Details

In docling/models/factories/base_factory.py, load_from_plugins() loads all entry points first and applies the allow_external_plugins check only to the already-imported modules. The CLI creates these factories when it starts, so running docling imports every registered plugin module. A log message says the plugin "will not be loaded", although its module has already been imported.

Affected configurations

Environments in which a package registering a docling plugin entry point is installed, for example an unvetted or compromised dependency, and which rely on allow_external_plugins=False to keep that code from running.

Impact

Execution of a third-party plugin module's import-time code in the docling process, contrary to the documented behaviour of allow_external_plugins=False.

Patches

Fixed in docling 2.131.0 by #4413. Plugin entry points are now filtered by module name before they are loaded, so with allow_external_plugins=False third-party plugin modules are no longer imported.

Workarounds

Upgrade to 2.131.0. For older versions:

Only install trusted packages in environments that run docling. Check which packages register docling plugin entry points with importlib.metadata.entry_points().

Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
6.7

The vulnerability requires local access to the device to be exploited. It is difficult for an attacker to exploit this vulnerability and may require special conditions. An attacker needs basic access or low-level privileges. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.

Threat Intelligence
6.1

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.12%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard