GHSA-87cf-j763-vvh8 · Severity: high · Ecosystem: maven — OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue.
Conclusion & alert: CVE-2024-47881 is rated High Exploit Risk (64/100): CVSS High severity, with low exploitation likelihood (EPSS 0.66%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.35% | 0.66% | +0.30% |
| 2 | 2026-06-08 | 0.29% | 0.35% | +0.06% |
| 3 | 2026-03-21 | — | 0.29% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.8 | 5.2 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-87cf-j763-vvh8 · Severity: high · Ecosystem: maven — OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2024-47881 not yet assigned priority: Debian including 1 source packages (openrefine), 4 status rows across 4 suites (bookworm, forky, sid, trixie): resolved 4. | https://security-tracker.debian.org/tracker/CVE-2024-47881 |
ubuntu
|
medium | CVE-2024-47881 medium priority: Ubuntu including 1 source packages (openrefine), 7 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): released 4, not-affected 2, DNE 1. | https://ubuntu.com/security/CVE-2024-47881 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openrefine | openrefine | >= 3.4, < 3.8.3 | cpe:2.3:a:openrefine:openrefine:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/OpenRefine/OpenRefine/commit/853a1d91662e7dc278a9a94a38be58de04494056 | Patch |
| https://github.com/OpenRefine/OpenRefine/security/advisories/GHSA-87cf-j763-vvh8 | Exploit Third Party Advisory |