{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-108553","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-10-10T14:39:40.008Z","datePublished":"2026-10-10T14:49:38.768Z","dateUpdated":"2026-10-10T14:49:38.768Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-10-10T14:49:38.768Z"},"datePublic":"2026-10-01T00:00:00.000Z","title":"OpenRefine through 3.10.1 CSRF to RCE via get-rows Command","descriptions":[{"lang":"en","value":"OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Cross-Site Request Forgery (CSRF)","cweId":"CWE-352","type":"CWE"}]}],"affected":[{"vendor":"OpenRefine","product":"OpenRefine","defaultStatus":"unaffected","packageURL":"pkg:maven/org.openrefine/openrefine","versions":[{"version":"0","lessThanOrEqual":"3.10.1","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*","versionEndIncluding":"3.10.1"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}],"references":[{"url":"https://github.com/OpenRefine/OpenRefine/issues/7999","tags":["issue-tracking"],"name":"GitHub Issue #7999"},{"url":"https://github.com/OpenRefine/OpenRefine","tags":["product"]},{"url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java#L174-L186","tags":["technical-description"]},{"url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java#L327-L339","tags":["technical-description"]},{"url":"https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java#L142","tags":["technical-description"]},{"name":"VulnCheck Advisory: OpenRefine through 3.10.1 CSRF to RCE via get-rows Command","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command"}],"credits":[{"lang":"en","value":"George Chen","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}}}}