CVE-2026-27194
D-Tale affected by Remote Code Execution through the /save-column-filter endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in version 3.20.0.
| CWE | CWE-74 |
| Vendor | man-group |
| Product | dtale |
| Published | Feb 21, 2026 |
| Last Updated | Feb 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for man-group dtale
Be the first to know when new unknown vulnerabilities affecting man-group dtale are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
man-group / dtale
< 3.20.0