<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenRefine (&lt;= 3.10.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/openrefine--3.10.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 15:55:52 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/openrefine--3.10.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CSRF Vulnerability in OpenRefine Leading to Remote Code Execution</title><link>https://feed.craftedsignal.io/briefs/2026-10-openrefine-csrf/</link><pubDate>Sat, 10 Oct 2026 15:55:52 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-openrefine-csrf/</guid><description>OpenRefine versions up to 3.10.1 are vulnerable to a cross-site request forgery attack in the get-rows command that permits remote attackers to execute arbitrary Jython facet expressions and achieve system command execution.</description><content:encoded><![CDATA[<p>OpenRefine versions through 3.10.1 contain a critical cross-site request forgery (CSRF) vulnerability residing within the get-rows command. This flaw allows a remote, unauthenticated attacker to execute arbitrary Jython facet expressions on the host server by inducing an authenticated OpenRefine user to visit a malicious, attacker-controlled webpage. Because OpenRefine facilitates data processing, the ability to inject and execute Jython code via the engine parameter during a cross-origin GET request can result in full remote command execution (RCE) with the privileges of the user running the OpenRefine application. This is particularly significant for local instances where the application is intended for trusted data cleaning but may be exposed to browser-based threats from the user's active session.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for remote command execution under the security context of the user running OpenRefine. This can lead to complete host compromise, unauthorized access to sensitive datasets processed by the application, and the potential for lateral movement within the network if the instance is deployed in a multi-user or server-based environment.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Identify all instances of OpenRefine running in the environment using asset management tools or process monitoring.</li>
<li>Upgrade all OpenRefine installations to a patched version beyond 3.10.1 as soon as an update is released by the vendor.</li>
<li>Implement restrictive network access controls to ensure the OpenRefine management interface is not accessible from external, untrusted network segments.</li>
<li>Disable Jython script execution features if they are not required for specific data transformation workflows.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>csrf</category><category>rce</category></item></channel></rss>