CVE-2026-108553
EUVD-2026-9634710.10.2026, 15:16
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openrefine | openrefine | 𝑥 ≤ 3.10.1 | CNA |
Common Weakness Enumeration
References