Impact
This vulnerability allows a remote attacker to trick a user into triggering a cross‑site request forgery (CSRF) against the OpenRefine get‑rows command. By supplying a crafted engine parameter, the victim’s browser initiates a GET request that causes OpenRefine to evaluate a Jython facet expression, which in turn executes arbitrary operating‑system commands under the OpenRefine process user. The result is uncontrolled code execution on the host running the OpenRefine web service.
Affected Systems
All OpenRefine instances up to and including version 3.10.1 are affected. The vulnerability exists in the OpenRefine:OpenRefine product line; any deployment of these versions running the default configuration is at risk.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, but the nature of the attack—requiring only a malicious web page to lure a user—makes exploitation plausible in environments where users access OpenRefine from browsers. The CSRF vector requires victim interaction, yet the effect is remote code execution, which can compromise the entire server. Users should consider the risk high and prioritize remediation.
OpenCVE Enrichment