docling-core is vulnerable to Deserialization of Untrusted Data
70
High Risk
Affected versions of this package are vulnerable to Arbitrary Code Execution due to unsafe YAML deserialization. They use yaml.load() with loader=yaml.FullLoader to process untrusted YAML input. An attacker can exploit this by supplying a maliciously crafted YAML file containing embedded Python commands, which are executed during deserialization and can potentially lead to full system compromise.
You are affected if you are using a version that falls within the vulnerable range.
docling-core is vulnerable to Deserialization of Untrusted Data in versions 2.21.0 - 2.48.3.
Upgrade the docling-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant