CVE-2026-108553 PUBLISHED

OpenRefine through 3.10.1 CSRF to RCE via get-rows Command

Assigner: VulnCheck
Reserved: 10.10.2026 Published: 10.10.2026 Updated: 10.10.2026

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor OpenRefine
Product OpenRefine
Versions Default: unaffected
  • affected from 0 to 3.10.1 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE