Vendor
OpenRefine versions up to 3.10.1 are vulnerable to a cross-site request forgery attack in the get-rows command that permits remote attackers to execute arbitrary Jython facet expressions and achieve system command execution.