dtale
Web Client for Visualizing Pandas Objects
Activity
- Latest release
- 5mo ago
- Total releases
- 177
- Cadence
- ~13 days
- Last 12 months
- 5
Reach
- Stars
- —
Details
- License
- LGPL-3.0
- First release
- Sep 07, 2019
| Version | Released | |
|---|---|---|
3.22.0
minor
| ||
3.21.0
minor
1 CVE
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.20.0
minor
1 CVE
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.19.1
patch
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.19.0
minor
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.18.2
patch
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.18.1
patch
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.18.0
minor
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.17.0
minor
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.16.1
patch
2 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.16.0
minor
3 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.15.1
patch
3 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.15.0
minor
3 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.14.1
patch
3 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.14.0
minor
5 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.13.1
patch
5 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.13.0
minor
5 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.12.0
minor
5 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.11.0
minor
5 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
3.10.0
minor
6 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.9.0
minor
6 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.8.1
patch
7 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.8.0
minor
7 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.7.0
minor
7 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.6.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.5.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.4.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.3.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.2.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.1.7
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.1.6
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.1.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
3.0.0
major
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.16.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.15.2
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.15.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.14.1
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.14.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.13.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.12.3
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.12.2
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.12.1
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.12.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.11.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.10.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.9.1
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.9.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.8.1
patch
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.8.0
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
2.7.1
minor
8 CVEs
CVE-2026-35052
PYSEC-2026-2460
GHSA-436g-fhfc-9g5w
Jul 13, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Low
Network
Low
None
ImpactUsers hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.22.0. WorkaroundsThere are no workarounds for versions < 3.22.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 164 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.20.0
3.21.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.22.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27194
PYSEC-2026-2461
GHSA-c87c-78rc-vmv2
Jul 13, 2026
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
Critical
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.20.0. WorkaroundsThere are no workarounds for versions < 3.20.0 Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 162 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.16.1
3.17.0
3.18.0
3.18.1
3.18.2
3.19.0
3.19.1
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.20.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-55890
PYSEC-2026-1320
GHSA-832w-fhmw-w4f4
Jul 07, 2026
D-Tale allows Remote Code Execution through the Custom Filter Input
Low
Network
Low
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.16.1 where the WorkaroundsThe only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 155 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.14.1
3.15.0
3.15.1
3.16.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.16.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-8862
PYSEC-2026-1321
GHSA-fg5m-m723-7mv6
Jul 07, 2026
D-Tale Command Execution Vulnerability
Medium
Network
Low
None
None
D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures. In dtale\views.py, under the route @dtale.route("/chart-data/<data_id>"), the query parameters from the request are directly passed into run_query for execution. And the run_query function calls proceed without performing any processing or sanitization of the query parameter. As a result, the query is directly used in the df.query method for data retrieval. Tthe engine used is Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-45595
PYSEC-2026-1323
GHSA-pw44-4h99-wqff
Jul 07, 2026
D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
Medium
Network
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 151 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.11.0
3.12.0
3.13.0
3.13.1
3.14.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
Fixed in
3.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-21642
PYSEC-2026-1319
GHSA-7hfx-h3j3-rwq4
Jul 07, 2026
D-Tale server-side request forgery through Web uploads
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactUsers hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server. PatchesUsers should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users. ReferencesSee "Load Data & Sample Datasets" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 144 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
Fixed in
3.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-46134
PYSEC-2026-1322
GHSA-jq6c-r9xf-qxjm
Jul 07, 2026
dtale vulnerable to Remote Code Execution through the Custom Filter Input
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsers hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. PatchesUsers should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here WorkaroundsThe only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users. ReferencesSee "Custom Filter" documentation Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 141 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
Fixed in
3.7.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-3408
GHSA-v9q6-fm48-rx74
PYSEC-2024-117
Jun 06, 2024
Authentication bypass in dtale
High
Network
Low
None
None
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded Affected versions
1.0.0
1.1.1
1.10.0
1.11.0
1.12.1
1.13.0
1.14.1
1.15.2
1.16.0
1.17.0
1.18.2
1.19.2
+ 146 more Show less
1.2.0
1.20.0
1.21.1
1.22.0
1.22.1
1.23.0
1.24.0
1.25.0
1.26.0
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.3.7
1.30.0
1.31.0
1.32.0
1.32.1
1.33.0
1.33.1
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.4.1
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.43.0
1.44.0
1.44.1
1.45.0
1.46.0
1.47.0
1.48.0
1.49.0
1.5.1
1.50.0
1.50.1
1.51.0
1.52.0
1.53.0
1.54.0
1.54.1
1.55.0
1.56.0
1.57.0
1.58.1
1.58.2
1.58.3
1.59.0
1.59.1
1.6.10
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.60.1
1.60.2
1.61.0
1.61.1
1.7.0
1.7.1
1.7.10
1.7.11
1.7.12
1.7.13
1.7.14
1.7.15
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.3
1.8.4
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.2
2.0.0
2.1.0
2.1.2
2.10.0
2.11.0
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.14.0
2.14.1
2.15.0
2.15.2
2.16.0
2.2.0
2.3.0
2.4.0
2.5.1
2.6.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
3.0.0
3.1.0
3.1.6
3.1.7
3.10.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
References
Updated Jun 10, 2026 · Source: OSV.dev |