Intel

AIKIDO-2026-696810

lfx-docling is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-j8f7-x8jm-wmm4 Published Today

63

Medium Risk

This Affects:

PYTHONlfx-docling
0.1.0 - 0.1.1
Fixed in 0.1.2
Are you affected? Scan for Free

TL;DR

The Docling Serve component builds an HTTP client for a base URL taken from the flow and does not apply the SSRF guard. A signed-in user who can build a flow can point that base URL at a loopback, private, or metadata address and read the response. The fix builds the client with the SSRF-protected settings for that URL.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and signed-in users can run a flow that calls Docling Serve.

Background info

lfx-docling is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.1.0 - 0.1.1.

How to fix this

Upgrade the lfx-docling library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform