CVE-2026-108553
Received Received - Intake

Cross-Site Request Forgery in OpenRefine Leading to Jython Command Execution

Vulnerability report for CVE-2026-108553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OpenRefine OpenRefine 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenRefine through 3.10.1 has a cross-site request forgery (CSRF) vulnerability in the get-rows command. Attackers can trick users into visiting a malicious page that sends a crafted GET request with a malicious engine parameter. This executes Jython facet expressions, allowing remote code execution on the system running OpenRefine.

Detection Guidance

Check OpenRefine logs for unusual GET requests to /command/core/get-rows with crafted parameters. Monitor network traffic for outbound connections initiated by OpenRefine processes. Inspect Jython facet expressions for unexpected code execution attempts.

Impact Analysis

An attacker could execute arbitrary operating system commands on your machine as the OpenRefine user. This requires minimal user interaction, such as loading an image tag, and leaves no visible trace. The attack is unauthenticated, meaning no login is required.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially exposing sensitive data processed by OpenRefine. For GDPR, this may result in violations of data confidentiality and integrity requirements. Under HIPAA, it could compromise protected health information if such data is processed by the tool. The lack of CSRF protection and ability to execute arbitrary commands may violate compliance controls requiring access controls and audit logging.

Mitigation Strategies

Upgrade OpenRefine to the latest version beyond 3.10.1. Disable Jython facet expressions if not required. Implement network-level protections to block unauthorized GET requests to OpenRefine endpoints. Apply CSRF tokens to all state-changing requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart