© 2025-2026 PySpect
First version without a known vulnerability: 2.94.0
Docling: Unsafe URI and Path Handling in HTML Backend
Fixed in: 2.94.0
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Fixed in: 2.91.0
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
Fixed in: 2.74.0
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Fixed in: 2.91.0
Docling: Unsafe Playwright-based HTML Rendering
Fixed in: 2.91.0
Docling: Unsafe Zip Extraction in EasyOCR Model Download
Fixed in: 2.91.0
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks