<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:fsspec_project:fsspec:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afsspec_projectfsspec/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:46:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afsspec_projectfsspec/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution via Server-Side Template Injection in fsspec ReferenceFileSystem</title><link>https://feed.craftedsignal.io/briefs/2026-10-fsspec-ssti/</link><pubDate>Tue, 06 Oct 2026 00:46:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fsspec-ssti/</guid><description>The fsspec library contains an un-sandboxed Jinja2 template injection vulnerability in its Kerchunk reference processing logic, allowing arbitrary code execution when processing malicious data catalogues.</description><content:encoded><![CDATA[<p>The <code>fsspec</code> library, specifically the <code>ReferenceFileSystem</code> implementation used for the Kerchunk data format, contains an un-sandboxed Server-Side Template Injection (SSTI) vulnerability. The parser processes &quot;references&quot; JSON documents and renders fields using <code>jinja2.Template(...).render(...)</code> without security restrictions. Vulnerable sinks exist within the <code>_process_references1._render_jinja</code>, <code>_process_templates</code>, and <code>_process_gen</code> methods in <code>fsspec/implementations/reference.py</code>.</p>
<p>An attacker who controls a references JSON document can achieve arbitrary Python code execution on the victim's machine. This occurs as soon as the victim opens the file using <code>fsspec.filesystem(&quot;reference&quot;, fo=URL)</code> or via high-level consumers such as <code>xarray.open_dataset</code>. This vulnerability impacts all versions from 0.9.0 through 2026.5.x. The exploitation path mirror patterns seen in previous Jinja2-based RCE vulnerabilities where externally-sourced templates were rendered in unrestricted environments.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious JSON document containing Jinja2 SSTI payloads (e.g., using <code>__init__.__globals__</code> to access system commands).</li>
<li>Attacker hosts the malicious JSON document at a public or accessible URL.</li>
<li>Attacker induces a victim (e.g., a data scientist or automated pipeline) to load the URL using <code>fsspec</code> or a library that consumes it, such as <code>xarray</code>.</li>
<li>The victim application calls <code>fsspec.filesystem(&quot;reference&quot;, fo=URL)</code> to initialize the filesystem.</li>
<li>The <code>ReferenceFileSystem</code> logic parses the JSON and reaches one of the vulnerable sinks, specifically <code>_process_gen</code>, which is triggered unconditionally for any JSON containing a <code>gen</code> field.</li>
<li>The <code>jinja2.Template.render</code> call processes the malicious payload.</li>
<li>The Jinja2 environment executes the injected Python code on the host machine.</li>
<li>The attacker achieves arbitrary code execution (RCE) with the privileges of the victim application.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary remote code execution on systems processing Kerchunk data catalogues. This is critical for the Pangeo, Earth-observation, and climate data-science ecosystems, where Kerchunk is widely adopted. Impacted environments include interactive Jupyter notebook servers, automated batch processing pipelines, and local analysis workstations. Victims are compromised immediately upon opening a malicious reference file, leading to potential data exfiltration or lateral movement within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following actions to mitigate this vulnerability:</p>
<ul>
<li>Upgrade <code>fsspec</code> to version 2026.6.0 or later immediately to incorporate the sandboxed environment fix.</li>
<li>Implement strict network filtering on internal data-science environments to restrict outbound connections to untrusted storage URLs.</li>
<li>Audit all automated pipelines consuming Kerchunk files to ensure they are not processing files from unverified or user-controlled sources.</li>
<li>Patch CVE-2026-104851 across all production and development environments using <code>fsspec</code>.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>rce</category><category>vulnerability</category><category>python</category></item></channel></rss>