CVE-2026-104851: fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution

Published Oct 2, 2026
·
Updated

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in processreferences1.renderjinja, processtemplates, and processgen in fsspec/implementations/reference.py. A document supplied inline or fetched from an attacker-controlled URL can provide template expressions that execute Python code when the reference filesystem is opened, including through consumers such as xarray, before referenced data is read. The processgen path is reached whenever a document includes a gen array, while the other paths depend on template-related options and values. This issue is fixed in version 2026.6.0.

Affected Software

1 affected component
pypi/fsspec>=0.9.0<2026.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade fsspec to a version that resolves this vulnerability.

    Fixed in 2026.6.0

Event History

Oct 2, 2026
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using fsspec versions from 0.9.0 through versions before 2026.6.0 are affected if they open Kerchunk reference JSON supplied inline or retrieved from an attacker-controlled URL. Consumers such as xarray can trigger processing when opening the reference filesystem, before any referenced data is read.

2

What must an attacker provide to exploit this issue?

An attacker needs to cause the application to process a crafted Kerchunk reference JSON document. The document can contain Jinja template expressions that are rendered without restriction; a gen array reaches the vulnerable _process_gen path, while other paths depend on template-related options and values.

3

Is user interaction required?

The CVSS vector indicates user interaction is required. In practice, exploitation occurs when a user or application opens a crafted reference filesystem or processes a malicious reference document.

4

What version fixes the vulnerability?

The issue is fixed in fsspec version 2026.6.0. Upgrade affected installations to that version or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203