Page 1 of 1

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

Posted: Wed Nov 27, 2024 4:22 am
by Shane1145
A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems.

Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially crafted project in versions 3.7.3 and below.

https://thehackernews.com/2023/10/openr ... ility.html