CVE-2024-45595Medium· 6.1▾ SunlitD-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.7%
0.7% → 0.8%
Last analysed / modified upstream
Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server.
Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on here
The only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users.
See "Custom Filter" documentation
dtale < 3.14.1Upgrade to a patched release:
dtale 3.14.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-8862High· 7.3D-Tale Command Execution Vulnerability
CVE-2024-55890MediumD-Tale allows Remote Code Execution through the Custom Filter Input
CVE-2026-27194HighD-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVE-2026-35052MediumD-Tale: Remote Code Execution through redis/shelf storage
CVE-2023-46134Medium· 6.1dtale vulnerable to Remote Code Execution through the Custom Filter Input
CVE-2024-21642High· 7.5D-Tale server-side request forgery through Web uploads