CVE-2024-45595

MEDIUM

MAN D-tale < 3.14.1 - XSS

Title source: rule
STIX 2.1

Description

D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.14.1 where the "Custom Filter" input is turned off by default.

Scores

CVSS v3 6.1
EPSS 0.0163
EPSS Percentile 82.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
man/d-tale < 3.14.1
pypi/dtale 0 - 3.14.1PyPI
Published Sep 10, 2024
Tracked Since Feb 18, 2026