๐Ÿ” CVE Alert

CVE-2026-108553

HIGH 7.5

OpenRefine through 3.10.1 CSRF to RCE via get-rows Command

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

CWE CWE-352
Vendor openrefine
Product openrefine
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for openrefine openrefine

Be the first to know when new high vulnerabilities affecting openrefine openrefine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

OpenRefine / OpenRefine
0 โ‰ค 3.10.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OpenRefine/OpenRefine/issues/7999 github.com: https://github.com/OpenRefine/OpenRefine github.com: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java#L174-L186 github.com: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java#L327-L339 github.com: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java#L142 vulncheck.com: https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command

Credits

George Chen