CVE-2024-21642High· 7.5▾ TwilightD-Tale server-side request forgery through Web uploads
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.7%
Last analysed / modified upstream
Users hosting D-Tale publicly can be vulnerable to server-side request forgery (SSRF) allowing attackers to access files on the server.
Users should upgrade to version 3.9.0 where the "Load From the Web" input is turned off by default. You can find out more information on how to turn it back on here
The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users.
See "Load Data & Sample Datasets" documentation
dtale < 3.9.0Upgrade to a patched release:
dtale 3.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2026-35052MediumD-Tale: Remote Code Execution through redis/shelf storage
CVE-2024-45595Medium· 6.1D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
CVE-2023-46134Medium· 6.1dtale vulnerable to Remote Code Execution through the Custom Filter Input
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
CVE-2024-55890MediumD-Tale allows Remote Code Execution through the Custom Filter Input