Remote Code Execution via Server-Side Template Injection in fsspec ReferenceFileSystem
The fsspec library contains an un-sandboxed Jinja2 template injection vulnerability in its Kerchunk reference processing logic, allowing arbitrary code execution when processing malicious data catalogues.
CVE search metadata
CVE search record: CVE-2026-104851. Severity: high. CVSS: 8.8. EPSS: 0.32%. KEV: no. Product: fsspec (>= 0.9.0, < 2026.6.0). Brief: Remote Code Execution via Server-Side Template Injection in fsspec ReferenceFileSystem. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fsspec-ssti/
The fsspec library, specifically the ReferenceFileSystem implementation used for the Kerchunk data format, contains an un-sandboxed Server-Side Template Injection (SSTI) vulnerability. The parser processes "references" JSON documents and renders fields using jinja2.Template(...).render(...) without security restrictions. Vulnerable sinks exist within the _process_references1._render_jinja, _process_templates, and _process_gen methods in fsspec/implementations/reference.py.
An attacker who controls a references JSON document can achieve arbitrary Python code execution on the victim's machine. This occurs as soon as the victim opens the file using fsspec.filesystem("reference", fo=URL) or via high-level consumers such as xarray.open_dataset. This vulnerability impacts all versions from 0.9.0 through 2026.5.x. The exploitation path mirror patterns seen in previous Jinja2-based RCE vulnerabilities where externally-sourced templates were rendered in unrestricted environments.
Attack Chain
- Attacker crafts a malicious JSON document containing Jinja2 SSTI payloads (e.g., using
__init__.__globals__to access system commands). - Attacker hosts the malicious JSON document at a public or accessible URL.
- Attacker induces a victim (e.g., a data scientist or automated pipeline) to load the URL using
fsspecor a library that consumes it, such asxarray. - The victim application calls
fsspec.filesystem("reference", fo=URL)to initialize the filesystem. - The
ReferenceFileSystemlogic parses the JSON and reaches one of the vulnerable sinks, specifically_process_gen, which is triggered unconditionally for any JSON containing agenfield. - The
jinja2.Template.rendercall processes the malicious payload. - The Jinja2 environment executes the injected Python code on the host machine.
- The attacker achieves arbitrary code execution (RCE) with the privileges of the victim application.
Impact
Successful exploitation results in arbitrary remote code execution on systems processing Kerchunk data catalogues. This is critical for the Pangeo, Earth-observation, and climate data-science ecosystems, where Kerchunk is widely adopted. Impacted environments include interactive Jupyter notebook servers, automated batch processing pipelines, and local analysis workstations. Victims are compromised immediately upon opening a malicious reference file, leading to potential data exfiltration or lateral movement within the environment.
Recommendation
Prioritize the following actions to mitigate this vulnerability:
- Upgrade
fsspecto version 2026.6.0 or later immediately to incorporate the sandboxed environment fix. - Implement strict network filtering on internal data-science environments to restrict outbound connections to untrusted storage URLs.
- Audit all automated pipelines consuming Kerchunk files to ensure they are not processing files from unverified or user-controlled sources.
- Patch CVE-2026-104851 across all production and development environments using
fsspec.
Immediate actions
Upgrade fsspec to 2026.6.0 or later
Mitigations
Upgrade fsspec to 2026.6.0 or later
CVE-2026-104851