{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenrefineopenrefine/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108553"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenRefine (\u003c= 3.10.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","csrf","rce"],"_cs_type":"advisory","_cs_vendors":["OpenRefine"],"content_html":"\u003cp\u003eOpenRefine versions through 3.10.1 contain a critical cross-site request forgery (CSRF) vulnerability residing within the get-rows command. This flaw allows a remote, unauthenticated attacker to execute arbitrary Jython facet expressions on the host server by inducing an authenticated OpenRefine user to visit a malicious, attacker-controlled webpage. Because OpenRefine facilitates data processing, the ability to inject and execute Jython code via the engine parameter during a cross-origin GET request can result in full remote command execution (RCE) with the privileges of the user running the OpenRefine application. This is particularly significant for local instances where the application is intended for trusted data cleaning but may be exposed to browser-based threats from the user's active session.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote command execution under the security context of the user running OpenRefine. This can lead to complete host compromise, unauthorized access to sensitive datasets processed by the application, and the potential for lateral movement within the network if the instance is deployed in a multi-user or server-based environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of OpenRefine running in the environment using asset management tools or process monitoring.\u003c/li\u003e\n\u003cli\u003eUpgrade all OpenRefine installations to a patched version beyond 3.10.1 as soon as an update is released by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement restrictive network access controls to ensure the OpenRefine management interface is not accessible from external, untrusted network segments.\u003c/li\u003e\n\u003cli\u003eDisable Jython script execution features if they are not required for specific data transformation workflows.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T15:55:52Z","date_published":"2026-10-10T15:55:52Z","id":"https://feed.craftedsignal.io/briefs/2026-10-openrefine-csrf/","summary":"OpenRefine versions up to 3.10.1 are vulnerable to a cross-site request forgery attack in the get-rows command that permits remote attackers to execute arbitrary Jython facet expressions and achieve system command execution.","title":"CSRF Vulnerability in OpenRefine Leading to Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-10-openrefine-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}