D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0.
References
Configurations
History
23 Feb 2026, 20:47
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:man:d-tale:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Man
Man d-tale |
|
| References | () https://github.com/man-group/dtale/commit/431c6148d3c799de20e1dec86c4432f48e3d0746 - Patch | |
| References | () https://github.com/man-group/dtale/security/advisories/GHSA-c87c-78rc-vmv2 - Vendor Advisory |
21 Feb 2026, 05:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-21 05:17
Updated : 2026-02-23 20:47
NVD link : CVE-2026-27194
Mitre link : CVE-2026-27194
CVE.ORG link : CVE-2026-27194
JSON object : View
Products Affected
man
- d-tale
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
