Sceawere

Vulnerability Detail

CVE-2026-108553UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenRefine CSRF Remote Code Execution

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
OpenRefine
Product
OpenRefine
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-10T15:16:58.410Z",
  "pubdate": "2026-10-10T15:16:58.410Z",
  "executiveSummary": "OpenRefine versions up to 3.10.1 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability located within the 'get-rows' command. This vulnerability allows an unauthenticated remote attacker to execute arbitrary operating system commands with the privileges of the OpenRefine user process.\nThe vulnerability originates from the application's failure to adequately validate origin headers or utilize CSRF tokens for state-changing operations. An attacker can craft a malicious web page that, when visited by an authenticated user of OpenRefine, triggers a cross-origin GET request with a weaponized 'engine' parameter.\nBecause the 'get-rows' command can be manipulated to invoke Jython facet expressions, the attack leads to Remote Code Execution (RCE). The impact is critical, as it bypasses intended authorization boundaries, allowing attackers to compromise the host system's integrity and confidentiality. Successful exploitation requires a victim to possess an active OpenRefine session and to interact with malicious content. Organizations should prioritize restricting access to the application interface and ensuring that the service is not exposed to untrusted web environments.",
  "technicalDetails": "The vulnerability exists in the handling of the 'get-rows' command component within OpenRefine, which fails to implement robust CSRF protection. In web applications, CSRF protection typically relies on unique, non-predictable tokens or the validation of Origin/Referer headers to prevent unauthorized cross-site requests. The absence of these mechanisms in the 'get-rows' command enables an attacker to force an authenticated user's browser to send an arbitrary request to the OpenRefine server.\nThe attack flow proceeds as follows: First, the attacker hosts a malicious website containing a cross-origin request targeting the OpenRefine server API. Second, the attacker entices an authenticated OpenRefine user to navigate to the malicious site. Third, the victim's browser automatically includes the victim's session cookies in the forged request to the 'get-rows' endpoint. Fourth, the server processes the request, which includes a malicious 'engine' parameter containing a crafted Jython facet expression.\nJython is a Java implementation of Python that is integrated into OpenRefine for data transformation purposes. When the 'get-rows' command processes the user-provided 'engine' parameter, the underlying application logic evaluates the expression within the Jython execution environment. By embedding shell execution primitives within the Jython expression—such as those utilizing the 'os' or 'subprocess' modules—the attacker can break out of the application context and execute arbitrary system-level commands.\nThe payload behaves by hijacking the existing session context to bypass authentication and authorization checks. Because the request is treated as a legitimate user action, the Jython engine executes the malicious code with the same system-level permissions as the OpenRefine application process. This results in complete control over the host environment, enabling the attacker to exfiltrate data, install persistent backdoors, or pivot further into the local network.\nThe vulnerability affects all versions of OpenRefine through 3.10.1. Exploitation is particularly effective because it does not require knowledge of the target's internal network structure, provided the OpenRefine instance is reachable by the victim's browser. The lack of validation on the 'engine' parameter effectively turns a data processing feature into a powerful RCE primitive for any adversary capable of inducing a victim to trigger a CSRF attack."
}
CVE-2026-108553: OpenRefine CSRF Remote Code Execution (HIGH Severity, CVSS: 7.5) | Sceawere