---
id: CVE-2024-45595
aliases:
  - GHSA-pw44-4h99-wqff
  - PYSEC-2026-1323
title: >-
  D-Tale vulnerable to Remote Code Execution through the Query input on Chart
  Builder
summary: >-
  D-Tale vulnerable to Remote Code Execution through the Query input on Chart
  Builder
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
vendor: dtale
product: dtale
ecosystem: pip
affected:
  - dtale < 3.14.1
patched:
  - dtale 3.14.1
published: '2024-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:18.295937272Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pw44-4h99-wqff'
references:
  - url: 'https://github.com/man-group/dtale/security/advisories/GHSA-pw44-4h99-wqff'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-45595'
  - url: >-
      https://github.com/man-group/dtale/commit/b6e30969390520d1400b55acbb13e5487b8472e8
  - url: 'https://github.com/man-group/dtale'
  - url: 'https://github.com/man-group/dtale#custom-filter'
tags:
  - osv
  - pip
epss: 0.00782
epssPercentile: 0.54515
ingestedAt: '2026-07-08T18:25:52.021Z'
---

## Overview

### Impact
Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server.

### Patches
Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default. You can find out more information on how to turn it back on [here](https://github.com/man-group/dtale#custom-filter)

### Workarounds
The only workaround for versions earlier than 3.14.1 is to only host D-Tale to trusted users.

### References
See "Custom Filter" [documentation](https://github.com/man-group/dtale#custom-filter)


## Affected packages

- `dtale < 3.14.1`

## Remediation

Upgrade to a patched release:

- `dtale 3.14.1`
