CVE-2024-45595

MEDIUM

d-tale < 3.14.1 - Remote Code Execution via Custom Filter Input

Title source: llm
STIX 2.1

Description

D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default.

Scores

CVSS v3 6.1
EPSS 0.0074
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
man/d-tale < 3.14.1
pypi/dtale 0 - 3.14.1PyPI
Published Sep 10, 2024
Tracked Since Feb 18, 2026