---
id: CVE-2026-108553
title: >-
  OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability
  in the get-rows command that allows remote attackers to execute Jython facet
  expressions
summary: >-
  OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability
  in the get-rows command that allows remote attackers to execute Jython facet
  expressions. Attackers can lure a user to a malicious page issuing a
  cross-origin …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T15:16:58.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108553'
references:
  - url: 'https://github.com/OpenRefine/OpenRefine'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java#L142
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java#L174-L186
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java#L327-L339
    label: disclosure@vulncheck.com
  - url: 'https://github.com/OpenRefine/OpenRefine/issues/7999'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-10T15:25:58.088Z'
---

## Overview

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
