HarborGuard / CVE
Back to search
HIGHCVE-2026-27194Published Modified CNA GitHub_M

CVE-2026-27194: D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0.

Metrics

CVSS v4.0
8.1
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • man-group / dtale
    < 3.20.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U