PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108553 OpenRefine CVE debrief

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. This vulnerability can be exploited by luring a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, potentially leading to execution of operating system commands as the OpenRefine user. Defenders should assess exposure and prioritize verification and remediation efforts accordingly. The vulnerability highlights the importance of securing OpenRefine installations and restricting access to sensitive commands.

Vendor
OpenRefine
Product
Unknown
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for OpenRefine installations should assess exposure and prioritize verification and remediation efforts. This includes OpenRefine users, administrators, and security teams who need to ensure the security and integrity of their OpenRefine instances. Additionally, vulnerability management teams and security professionals responsible for OpenRefine installations should be aware of this vulnerability and take necessary actions to mitigate

Why it matters

Defenders should prioritize verifying OpenRefine installations and restricting access to the get-rows command due to a cross-site request forgery vulnerability.

  • Remote attackers can execute Jython facet expressions
  • Defenders must verify OpenRefine installations and restrict access
  • Additional verification is needed to confirm affected versions and remediation

Technical summary

The vulnerability exists in the get-rows command of OpenRefine through 3.10.1, allowing remote attackers to execute Jython facet expressions via a crafted engine parameter. This can be achieved by luring a user to a malicious page issuing a cross-origin GET request. The vulnerability highlights the need for defenders to prioritize verifying OpenRefine installations and restricting access to the get-rows command to prevent potential exploitation. OpenRefine users should assess their exposure and prioritize verification and remediation efforts accordingly.

Defensive priority

Defenders should prioritize verifying OpenRefine installations and restricting access to the get-rows command.

Recommended defensive actions

  • Verify OpenRefine installations for version 3.10.1 or earlier
  • Restrict access to the get-rows command
  • Monitor for suspicious activity on OpenRefine instances
  • Implement additional security measures such as input validation and content security policy
  • Conduct regular vulnerability assessments and penetration testing
  • Review and update incident response plans to address potential exploitation
  • Ensure proper logging and monitoring of OpenRefine instance activity

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional verification is needed to confirm affected versions and remediation. Further review of OpenRefine documentation and source code may be necessary to fully understand the vulnerability and develop effective mitigations. The vulnerability exists in the get-rows command, which allows remote attackers to execute Jython facet expressions via a crafted engine parameter. OpenRefine users should verify their installations and restrict access to the get-rows to 7

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108553 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108553

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108553 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108553

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/OpenRefine/OpenRefine

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/extensions/jython/src/com/google/refine/jython/JythonEvaluable.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/main/src/com/google/refine/commands/row/GetRowsCommand.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/OpenRefine/OpenRefine/blob/bde8a36dc188f7846aeafc2910969e7d0fbc8e7c/modules/core/src/main/java/com/google/refine/browsing/facets/ListFacet.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/OpenRefine/OpenRefine/issues/7999

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/openrefine-through-3.10.1-csrf-to-rce-via-get-rows-command

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.