CVE-2026-104851
Received Received - Intake

Template Injection in fsspec ReferenceFileSystem

Vulnerability report for CVE-2026-104851, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in _process_references1._render_jinja, _process_templates, and _process_gen in fsspec/implementations/reference.py. A document supplied inline or fetched from an attacker-controlled URL can provide template expressions that execute Python code when the reference filesystem is opened, including through consumers such as xarray, before referenced data is read. The _process_gen path is reached whenever a document includes a gen array, while the other paths depend on template-related options and values. This issue is fixed in version 2026.6.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
fsspec fsspec 2026.6.0
fsspec fsspec From 0.9.0 (inc) to 2026.6.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Template Injection (SSTI) vulnerability in the fsspec library's ReferenceFileSystem. It allows attackers who control a Kerchunk reference JSON document to execute arbitrary Python code on a victim's machine by injecting malicious template expressions. The vulnerability exists because the library renders fields from these JSON documents using unsandboxed Jinja2 templates without proper restrictions.

Detection Guidance

To detect this vulnerability, check if your system uses fsspec versions between 0.9.0 and 2026.6.0. Inspect installed packages with commands like 'pip show fsspec' or 'conda list fsspec'. If vulnerable, look for suspicious JSON files processed by ReferenceFileSystem, especially those with 'gen' fields or Jinja2 templates.

Impact Analysis

An attacker could trick you into opening a malicious JSON file via fsspec.filesystem or xarray, leading to arbitrary code execution on your system. This could result in data theft, system compromise, or further network infiltration. The attack requires user interaction and network access but no special privileges.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations using affected fsspec versions may face compliance violations, legal liabilities, and reputational damage if exploited.

Mitigation Strategies

Upgrade fsspec to version 2026.6.0 or later immediately. If upgrading is not possible, disable template processing by setting simple_templates=True in ReferenceFileSystem configurations. Avoid opening untrusted JSON files with fsspec or xarray.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104851. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart