{"id":"CVE-2026-27194","aliases":["GHSA-c87c-78rc-vmv2","PYSEC-2026-2461"],"url":"https://o3.security/vulnerability/CVE-2026-27194","summary":"D-Tale affected by Remote Code Execution through the /save-column-filter endpoint","details":"D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0.","published":"2026-02-21T04:25:38.628Z","modified":"2026-07-15T01:49:17.805867888Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dtale","fixedVersion":"3.20.0"}],"fix":{"url":"https://github.com/man-group/dtale/commit/431c6148d3c799de20e1dec86c4432f48e3d0746","label":"man-group/dtale@431c614"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27194.json"},{"type":"ADVISORY","url":"https://github.com/man-group/dtale/security/advisories/GHSA-c87c-78rc-vmv2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27194"},{"type":"FIX","url":"https://github.com/man-group/dtale/commit/431c6148d3c799de20e1dec86c4432f48e3d0746"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:17.805867888Z"}}