{"id":"CVE-2026-108553","title":"OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions","summary":"OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-352"],"published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T15:16:58.410","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108553","references":[{"url":"https://github.com/OpenRefine/OpenRefine","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java#L142","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java#L174-L186","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java#L327-L339","label":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenRefine/OpenRefine/issues/7999","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T15:25:58.088Z","slug":"CVE-2026-108553","body":"## Overview\n\nOpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}