Cross-Site Request Forgery in OpenRefine by OpenRefine Team
CVE-2026-108553
7.7HIGH
What is CVE-2026-108553?
OpenRefine versions up to and including 3.10.1 are susceptible to a cross-site request forgery (CSRF) vulnerability found in the get-rows command. This exploit enables remote attackers to manipulate victims into visiting a rogue page that sends a cross-origin GET request with a maliciously crafted engine parameter, consequently executing arbitrary operating system commands under the privileges of the OpenRefine user. This vulnerability can lead to unauthorized data manipulation and exposure.
Affected Version(s)
OpenRefine 0 <= 3.10.1
