{"id":"CVE-2024-55890","aliases":["GHSA-832w-fhmw-w4f4","PYSEC-2026-1320"],"url":"https://o3.security/vulnerability/CVE-2024-55890","summary":"D-Tale allows Remote Code Execution through the Custom Filter Input","details":"D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. Users should upgrade to version 3.16.1 where the `update-settings` endpoint blocks the ability for users to update the `enable_custom_filters` flag. The only workaround for versions earlier than 3.16.1 is to only host D-Tale to trusted users.","published":"2024-12-13T18:00:04.173Z","modified":"2026-07-15T01:49:15.759680767Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dtale","fixedVersion":"3.16.1"}],"fix":{"url":"https://github.com/man-group/dtale/commit/1e26ed3ca12fe83812b90f12a2b3e5fb0b740f7a","label":"man-group/dtale@1e26ed3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55890.json"},{"type":"ADVISORY","url":"https://github.com/man-group/dtale/security/advisories/GHSA-832w-fhmw-w4f4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55890"},{"type":"FIX","url":"https://github.com/man-group/dtale/commit/1e26ed3ca12fe83812b90f12a2b3e5fb0b740f7a"},{"type":"PACKAGE","url":"https://github.com/man-group/dtale#custom-filter"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:15.759680767Z"}}