Skip to content
fsspec Vulnerability Allows Remote Code Execution via JSON Parsing

fsspec Vulnerability Allows Remote Code Execution via JSON Parsing

First seen 6 Oct 2026, 10:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 11:27 UTC
  • •CVE-2026-104851 allows remote code execution via JSON parsing in fsspec.
  • •All versions from 0.9.0 onward are affected, with a CVSS score of 8.8.
  • •No active exploitation has been confirmed as of now.

A vulnerability (CVE-2026-104851) in fsspec's ReferenceFileSystem allows attackers to execute arbitrary Python code by manipulating a JSON document. This flaw affects all versions of fsspec from 0.9.0 onward, with the vulnerable code introduced in March 2021. Attackers can exploit this vulnerability by hosting a malicious JSON document that victims access through fsspec.filesystem or xarray.open_dataset. The issue mirrors a previous vulnerability (CVE-2024-34359) in llama-cpp-python, where un-sandboxed Jinja2 template rendering was also exploited. The vulnerability was published on October 2, 2026, and has a CVSS score of 8.8, indicating a high severity. Users are advised to mitigate the risk by updating to the latest version of fsspec. No evidence of has been reported yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-05-10
CVE-2024-34359 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
CVE-2026-104851 published
A critical vulnerability in fsspec was disclosed, allowing remote code execution through JSON parsing.
Advisories.Gitlab

More articles in this cluster (3)

Following this threat?

Track CVE-2024-34359 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of fsspec are affected?
All versions from 0.9.0 onward are affected by CVE-2026-104851.
Is there a patch available?
Yes, users are advised to update to the latest version of fsspec to mitigate the vulnerability.
Has this vulnerability been exploited in the wild?
No evidence of active exploitation has been reported as of now.