github.com fsspec Vulnerability Allows Remote Code Execution via JSON Parsing
Article Content
- •CVE-2026-104851 allows remote code execution via JSON parsing in fsspec.
- •All versions from 0.9.0 onward are affected, with a CVSS score of 8.8.
- •No active exploitation has been confirmed as of now.
A vulnerability (CVE-2026-104851) in fsspec's ReferenceFileSystem allows attackers to execute arbitrary Python code by manipulating a JSON document. This flaw affects all versions of fsspec from 0.9.0 onward, with the vulnerable code introduced in March 2021. Attackers can exploit this vulnerability by hosting a malicious JSON document that victims access through fsspec.filesystem or xarray.open_dataset. The issue mirrors a previous vulnerability (CVE-2024-34359) in llama-cpp-python, where un-sandboxed Jinja2 template rendering was also exploited. The vulnerability was published on October 2, 2026, and has a CVSS score of 8.8, indicating a high severity. Users are advised to mitigate the risk by updating to the latest version of fsspec. No evidence of has been reported yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2024-34359 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of fsspec are affected?
Is there a patch available?
Has this vulnerability been exploited in the wild?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…