Code Execution Vulnerability in fsspec by Python
CVE-2026-104851

8.8HIGH

Key Information:

Vendor

Fsspec

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104851?

The fsspec library, utilized for filesystem interfaces in Python, contains a flaw that allows remote code execution via specially crafted Kerchunk reference JSON documents. This vulnerability affects versions from 0.9.0 to 2026.6.0. By leveraging unrestricted template rendering, malicious users can inject Python code through template expressions found in documents fetched from an attacker-controlled URL or supplied inline. This issue is particularly sensitive as it can be exploited before data is even read, making it a critical concern for users of the library across various applications, including data processing libraries like xarray. The vulnerability has been addressed in version 2026.6.0.

Affected Version(s)

filesystem_spec >= 0.9.0, < 2026.6.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.