{"id":"CVE-2026-35052","aliases":["GHSA-436g-fhfc-9g5w","PYSEC-2026-2460"],"url":"https://o3.security/vulnerability/CVE-2026-35052","summary":"D-Tale affected by Remote Code Execution through redis/shelf storage","details":"D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.","published":"2026-04-06T17:32:28.227Z","modified":"2026-07-15T01:49:12.922908694Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dtale","fixedVersion":"3.22.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35052.json"},{"type":"ADVISORY","url":"https://github.com/man-group/dtale/security/advisories/GHSA-436g-fhfc-9g5w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35052"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:12.922908694Z"}}