CVE-2023-46134Medium· 6.1▾ Sunlitdtale vulnerable to Remote Code Execution through the Custom Filter Input
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.8%
Last analysed / modified upstream
Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server.
Users should upgrade to version 3.7.0 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here
The only workaround for versions earlier than 3.7.0 is to only host D-Tale to trusted users.
See "Custom Filter" documentation
dtale < 3.7.0Upgrade to a patched release:
dtale 3.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2026-35052MediumD-Tale: Remote Code Execution through redis/shelf storage
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
CVE-2024-55890MediumD-Tale allows Remote Code Execution through the Custom Filter Input
CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads