{"id":"CVE-2026-108553","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-108553","summary":"OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can…","details":"OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.","published":"2026-10-10T15:16:58.410","modified":"2026-10-10T15:16:58.410","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java#L142"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java#L174-L186"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java#L327-L339"},{"type":"WEB","url":"https://github.com/OpenRefine/OpenRefine/issues/7999"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-10T15:16:58.410"}}