lfx-docling is vulnerable to Server-Side Request Forgery (SSRF)
63
Medium Risk
The Docling Serve component builds an HTTP client for a base URL taken from the flow and does not apply the SSRF guard. A signed-in user who can build a flow can point that base URL at a loopback, private, or metadata address and read the response. The fix builds the client with the SSRF-protected settings for that URL.
You are affected if you are using a version that falls within the vulnerable range and signed-in users can run a flow that calls Docling Serve.
lfx-docling is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.1.0 - 0.1.1.
Upgrade the lfx-docling library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.