Code Execution Vulnerability in fsspec by Python
CVE-2026-104851
8.8HIGH
What is CVE-2026-104851?
The fsspec library, utilized for filesystem interfaces in Python, contains a flaw that allows remote code execution via specially crafted Kerchunk reference JSON documents. This vulnerability affects versions from 0.9.0 to 2026.6.0. By leveraging unrestricted template rendering, malicious users can inject Python code through template expressions found in documents fetched from an attacker-controlled URL or supplied inline. This issue is particularly sensitive as it can be exploited before data is even read, making it a critical concern for users of the library across various applications, including data processing libraries like xarray. The vulnerability has been addressed in version 2026.6.0.
Affected Version(s)
filesystem_spec >= 0.9.0, < 2026.6.0
