Docling CVE-2026-24009 Enables Python RCE
A remote code execution flaw in Docling's YAML parser (CVE-2026-24009) allowed attackers to execute Python code during document processing, patched in Core v2.48.4.
Source: Oligo Security
Read more: CyberSecBrief









