← Vulnerability feed

Vulnerability record · CVE-2024-47880 · published 24 October 2024

CVE-2024-47880: Openrefine cross-site scripting vulnerability

Openrefine · Openrefine

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An attacker could lead a user to a malicious page that submits a form POST that contains embedded JavaScript code. This code would then be included in the response, along with an attacker-controlled `Content-Type` header, and so potentially executed in the victim's browser as if it was part of OpenRefine. The attacker-provided code can do anything the user can do, including deleting projects, retrieving database passwords, or executing arbitrary Jython or Closure expressions, if those extensions are also present. The attacker must know a valid project ID of a project that contains at least one row. Version 3.8.3 fixes the issue.

6.9 CVSS 3.1 Medium EPSS 0.36% · top 73.2% CWE-79 · Cross-site scriptingCWE-348 · CWE-348
6.9CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An attacker could lead a user to a malicious page that submits a form POST that contains embedded JavaScript code. This code would then be included in the response, along with an attacker-controlled `Content-Type` header, and so potentially executed in the victim's browser as if it was part of OpenRefine. The attacker-provided code can do anything the user can do, including deleting projects, retrieving database passwords, or executing arbitrary Jython or Closure expressions, if those extensions are also present. The attacker must know a valid project ID of a project that contains at least one row. Version 3.8.3 fixes the issue.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-47880 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-41887Openrefine sql injection vulnerabilityOpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any…EPSS 43%8.8CVE-2024-47879Openrefine code injection vulnerabilityOpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre…EPSS 0.40%8.8CVE-2024-47881Openrefine sql injection vulnerabilityOpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extens…EPSS 0.65%7.8CVE-2023-37476Openrefine path traversal vulnerabilityOpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file can be used to trigger arbitrar…EPSS 0.63%7.5CVE-2024-23833Openrefine path traversal vulnerabilityOpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=…EPSS 1.00%7.5CVE-2023-41886Openrefine sql injection vulnerabilityOpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any …EPSS 1.00%7.5CVE-2019-3580Openrefine path traversal vulnerabilityOpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.EPSS 1.9%7.5CVE-2018-20157Openrefine xml external entity (xxe) vulnerabilityThe data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers t…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-47880), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.