CYBER CODE RED

Get real-time updates on Telegram

P4Verified

fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution

CVE-2026-104851 affects fsspec. CVSS base score 8.8 (HIGH, Vendor/CNA). EPSS 0.00317 (percentile 0.22436), scored 2026-10-04. Affected range: >= 0.9.0, < 2026.6.0. Fixed version: 2026.6.0.

Published

CVE
CVE-2026-104851
CWE
CWE-94, CWE-1336
Product
fsspec
CCR priority
35.3 /100 (P4)
CVSS
8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00317 · percentile 0.22436 · 2026-10-04
KEV
no

Affected products

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104851.html