{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fsspec--0.9.0--2026.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fsspec_project:fsspec:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-104851"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fsspec (\u003e= 0.9.0, \u003c 2026.6.0)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","rce","vulnerability","python"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe \u003ccode\u003efsspec\u003c/code\u003e library, specifically the \u003ccode\u003eReferenceFileSystem\u003c/code\u003e implementation used for the Kerchunk data format, contains an un-sandboxed Server-Side Template Injection (SSTI) vulnerability. The parser processes \u0026quot;references\u0026quot; JSON documents and renders fields using \u003ccode\u003ejinja2.Template(...).render(...)\u003c/code\u003e without security restrictions. Vulnerable sinks exist within the \u003ccode\u003e_process_references1._render_jinja\u003c/code\u003e, \u003ccode\u003e_process_templates\u003c/code\u003e, and \u003ccode\u003e_process_gen\u003c/code\u003e methods in \u003ccode\u003efsspec/implementations/reference.py\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAn attacker who controls a references JSON document can achieve arbitrary Python code execution on the victim's machine. This occurs as soon as the victim opens the file using \u003ccode\u003efsspec.filesystem(\u0026quot;reference\u0026quot;, fo=URL)\u003c/code\u003e or via high-level consumers such as \u003ccode\u003exarray.open_dataset\u003c/code\u003e. This vulnerability impacts all versions from 0.9.0 through 2026.5.x. The exploitation path mirror patterns seen in previous Jinja2-based RCE vulnerabilities where externally-sourced templates were rendered in unrestricted environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious JSON document containing Jinja2 SSTI payloads (e.g., using \u003ccode\u003e__init__.__globals__\u003c/code\u003e to access system commands).\u003c/li\u003e\n\u003cli\u003eAttacker hosts the malicious JSON document at a public or accessible URL.\u003c/li\u003e\n\u003cli\u003eAttacker induces a victim (e.g., a data scientist or automated pipeline) to load the URL using \u003ccode\u003efsspec\u003c/code\u003e or a library that consumes it, such as \u003ccode\u003exarray\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe victim application calls \u003ccode\u003efsspec.filesystem(\u0026quot;reference\u0026quot;, fo=URL)\u003c/code\u003e to initialize the filesystem.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eReferenceFileSystem\u003c/code\u003e logic parses the JSON and reaches one of the vulnerable sinks, specifically \u003ccode\u003e_process_gen\u003c/code\u003e, which is triggered unconditionally for any JSON containing a \u003ccode\u003egen\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ejinja2.Template.render\u003c/code\u003e call processes the malicious payload.\u003c/li\u003e\n\u003cli\u003eThe Jinja2 environment executes the injected Python code on the host machine.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary code execution (RCE) with the privileges of the victim application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary remote code execution on systems processing Kerchunk data catalogues. This is critical for the Pangeo, Earth-observation, and climate data-science ecosystems, where Kerchunk is widely adopted. Impacted environments include interactive Jupyter notebook servers, automated batch processing pipelines, and local analysis workstations. Victims are compromised immediately upon opening a malicious reference file, leading to potential data exfiltration or lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate this vulnerability:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003efsspec\u003c/code\u003e to version 2026.6.0 or later immediately to incorporate the sandboxed environment fix.\u003c/li\u003e\n\u003cli\u003eImplement strict network filtering on internal data-science environments to restrict outbound connections to untrusted storage URLs.\u003c/li\u003e\n\u003cli\u003eAudit all automated pipelines consuming Kerchunk files to ensure they are not processing files from unverified or user-controlled sources.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-104851 across all production and development environments using \u003ccode\u003efsspec\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:46:33Z","date_published":"2026-10-06T00:46:33Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fsspec-ssti/","summary":"The fsspec library contains an un-sandboxed Jinja2 template injection vulnerability in its Kerchunk reference processing logic, allowing arbitrary code execution when processing malicious data catalogues.","title":"Remote Code Execution via Server-Side Template Injection in fsspec ReferenceFileSystem","url":"https://feed.craftedsignal.io/briefs/2026-10-fsspec-ssti/"}],"language":"en","title":"CraftedSignal Threat Feed - Fsspec (\u003e= 0.9.0, \u003c 2026.6.0)","version":"https://jsonfeed.org/version/1.1"}