{"id":"CVE-2026-24009","aliases":["GHSA-vqxf-v2gg-x3hc","PYSEC-2026-1313"],"title":"docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage","summary":"docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"docling-core","product":"docling-core","ecosystem":"pip","affected":["docling-core >= 2.21.0, < 2.48.4"],"patched":["docling-core 2.48.4"],"published":"2026-01-22","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-vqxf-v2gg-x3hc","references":[{"url":"https://github.com/docling-project/docling-core/security/advisories/GHSA-vqxf-v2gg-x3hc"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24009"},{"url":"https://github.com/docling-project/docling-core/issues/482"},{"url":"https://github.com/docling-project/docling-core/commit/3e8d628eeeae50f0f8f239c8c7fea773d065d80c"},{"url":"https://github.com/advisories/GHSA-8q59-q68h-6hv4"},{"url":"https://github.com/docling-project/docling-core"},{"url":"https://github.com/docling-project/docling-core/releases/tag/v2.48.4"}],"tags":["osv","pip","exploit-available"],"epss":0.01557,"epssPercentile":0.73665,"ingestedAt":"2026-07-08T18:25:53.369Z","exploits":{"github":1,"githubRepos":["https://github.com/BiranPeretz/docling-core-CVE-2026-24009"],"checkedAt":"2026-09-21T15:28:31.249Z"},"exploitAvailable":true,"slug":"CVE-2026-24009","body":"## Overview\n\n### Impact\n\nA PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in `docling-core >=2.21.0, <2.48.4` and, specifically only if the application uses `pyyaml < 5.4` and invokes `docling_core.types.doc.DoclingDocument.load_from_yaml()` passing it untrusted YAML data.\n\n### Patches\n\nThe vulnerability has been patched in `docling-core` version **2.48.4**.\nThe fix mitigates the issue by switching `PyYAML` deserialization from `yaml.FullLoader` to `yaml.SafeLoader`, ensuring that untrusted data cannot trigger code execution.\n\n### Workarounds\n\nUsers who cannot immediately upgrade `docling-core` can alternatively ensure that the installed version of `PyYAML` is **5.4 or greater**, which supposedly patches CVE-2020-14343.\n\n### References\n\n* GitHub Issue: #482\n* Upstream Advisory: CVE-2020-14343\n* Fix Release: [v2.48.4](https://github.com/docling-project/docling-core/releases/tag/v2.48.4)\n\n## Affected packages\n\n- `docling-core >= 2.21.0, < 2.48.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `docling-core 2.48.4`","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":5026,"id":"CVE-2026-24009","ts":1788887229518,"field":"exploit_available","old":"false","new":"true"},{"seq":3909,"id":"CVE-2026-24009","ts":1788886360258,"field":"exploit_available","old":"true","new":"false"},{"seq":2731,"id":"CVE-2026-24009","ts":1788883026061,"field":"exploit_available","old":"false","new":"true"},{"seq":1760,"id":"CVE-2026-24009","ts":1788882430049,"field":"exploit_available","old":"true","new":"false"},{"seq":866,"id":"CVE-2026-24009","ts":1788881863044,"field":"exploit_available","old":"false","new":"true"}]}