Cross-Site Request Forgery in OpenRefine by OpenRefine Team
CVE-2026-108553

7.7HIGH

Key Information:

Vendor

Openrefine

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108553?

OpenRefine versions up to and including 3.10.1 are susceptible to a cross-site request forgery (CSRF) vulnerability found in the get-rows command. This exploit enables remote attackers to manipulate victims into visiting a rogue page that sends a cross-origin GET request with a maliciously crafted engine parameter, consequently executing arbitrary operating system commands under the privileges of the OpenRefine user. This vulnerability can lead to unauthorized data manipulation and exposure.

Affected Version(s)

OpenRefine 0 <= 3.10.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.