PatchSiren cyber security CVE debrief
CVE-2026-108553 OpenRefine CVE debrief
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. This vulnerability can be exploited by luring a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, potentially leading to execution of operating system commands as the OpenRefine user. Defenders should assess exposure and prioritize verification and remediation efforts accordingly. The vulnerability highlights the importance of securing OpenRefine installations and restricting access to sensitive commands.
- Vendor
- OpenRefine
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for OpenRefine installations should assess exposure and prioritize verification and remediation efforts. This includes OpenRefine users, administrators, and security teams who need to ensure the security and integrity of their OpenRefine instances. Additionally, vulnerability management teams and security professionals responsible for OpenRefine installations should be aware of this vulnerability and take necessary actions to mitigate
Why it matters
Defenders should prioritize verifying OpenRefine installations and restricting access to the get-rows command due to a cross-site request forgery vulnerability.
- Remote attackers can execute Jython facet expressions
- Defenders must verify OpenRefine installations and restrict access
- Additional verification is needed to confirm affected versions and remediation
Technical summary
The vulnerability exists in the get-rows command of OpenRefine through 3.10.1, allowing remote attackers to execute Jython facet expressions via a crafted engine parameter. This can be achieved by luring a user to a malicious page issuing a cross-origin GET request. The vulnerability highlights the need for defenders to prioritize verifying OpenRefine installations and restricting access to the get-rows command to prevent potential exploitation. OpenRefine users should assess their exposure and prioritize verification and remediation efforts accordingly.
Defensive priority
Defenders should prioritize verifying OpenRefine installations and restricting access to the get-rows command.
Recommended defensive actions
- Verify OpenRefine installations for version 3.10.1 or earlier
- Restrict access to the get-rows command
- Monitor for suspicious activity on OpenRefine instances
- Implement additional security measures such as input validation and content security policy
- Conduct regular vulnerability assessments and penetration testing
- Review and update incident response plans to address potential exploitation
- Ensure proper logging and monitoring of OpenRefine instance activity
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional verification is needed to confirm affected versions and remediation. Further review of OpenRefine documentation and source code may be necessary to fully understand the vulnerability and develop effective mitigations. The vulnerability exists in the get-rows command, which allows remote attackers to execute Jython facet expressions via a crafted engine parameter. OpenRefine users should verify their installations and restrict access to the get-rows to 7
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108553 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108553
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108553 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108553
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenRefine/OpenRefine
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenRefine/OpenRefine/issues/7999
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.