D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c87c-78rc-vmv2 | D-Tale affected by Remote Code Execution through the /save-column-filter endpoint |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 21 Feb 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0. | |
| Title | D-Tale affected by Remote Code Execution through the /save-column-filter endpoint | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-21T04:25:38.628Z
Reserved: 2026-02-18T19:47:02.154Z
Link: CVE-2026-27194
No data.
Status : Received
Published: 2026-02-21T05:17:29.123
Modified: 2026-02-21T05:17:29.123
Link: CVE-2026-27194
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA