fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution
fsspec.implementations.reference.ReferenceFileSystem parses a "references" JSON document (Kerchunk format) supplied either inline or via a URL. The parser renders fields from this JSON through un-sandboxed jinja2.Template(…).render(…) calls in three locations. An attacker who controls the JSON document — typically by hosting it at a URL that the victim opens with fsspec.filesystem("reference", fo=URL) or via xarray.open_dataset("reference://…") — achieves arbitrary Python code execution on the victim machine, before any data is read. This …