{"id":"CVE-2024-21642","aliases":["GHSA-7hfx-h3j3-rwq4","PYSEC-2026-1319"],"url":"https://o3.security/vulnerability/CVE-2024-21642","summary":"D-Tale server-side request forgery through Web uploads","details":"D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the `Load From the Web` input is turned off by default. The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users.","published":"2024-01-05T21:11:41.528Z","modified":"2026-07-15T01:49:06.111316557Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dtale","fixedVersion":"3.9.0"}],"fix":{"url":"https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2","label":"man-group/dtale@954f6be"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21642.json"},{"type":"ADVISORY","url":"https://github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21642"},{"type":"FIX","url":"https://github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2"},{"type":"PACKAGE","url":"https://github.com/man-group/dtale?tab=readme-ov-file#load-data--sample-datasets"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:06.111316557Z"}}