CVE-2023-37476

OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*

History

10 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-22
Summary OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources. OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrary code execution in the context of the OpenRefine process if a user can be convinced to import it. The vulnerability exists in all versions of OpenRefine up to and including 3.7.3. Users should update to OpenRefine 3.7.4 as soon as possible. Users unable to upgrade should only import OpenRefine projects from trusted sources.
References
  • () https://www.sonarsource.com/blog/openrefine-zip-slip -
  • () https://github.com/OpenRefine/OpenRefine/releases/tag/3.7.4 -
References (MISC) https://github.com/OpenRefine/OpenRefine/commit/e9c1e65d58b47aec8cd676bd5c07d97b002f205e - Patch () https://github.com/OpenRefine/OpenRefine/commit/e9c1e65d58b47aec8cd676bd5c07d97b002f205e - Patch
References (MISC) https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-m88m-crr9-jvqq - Vendor Advisory () https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-m88m-crr9-jvqq - Vendor Advisory

27 Jul 2023, 03:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:*
References (MISC) https://github.com/OpenRefine/OpenRefine/commit/e9c1e65d58b47aec8cd676bd5c07d97b002f205e - (MISC) https://github.com/OpenRefine/OpenRefine/commit/e9c1e65d58b47aec8cd676bd5c07d97b002f205e - Patch
References (MISC) https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-m88m-crr9-jvqq - (MISC) https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-m88m-crr9-jvqq - Vendor Advisory
First Time Openrefine
Openrefine openrefine

17 Jul 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-17 22:15

Updated : 2025-06-10 16:15


NVD link : CVE-2023-37476

Mitre link : CVE-2023-37476


JSON object : View

Products Affected

openrefine

  • openrefine
CWE

No CWE.