A vulnerability has been found in docling-project docling up to 2.90.x and classified as critical. This impacts an unknown function of the component Configuration File Handler. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-44022. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.