/Vulnerability Library

D-Tale <= 3.16.0 - Pre-Auth RCE via Pandas Query Injection

CVE-2024-55890
Verified

Description

D-Tale prior to version 3.16.1 contains a remote code execution caused by the `update-settings` endpoint allowing updates to `enable_custom_filters`, letting attackers run malicious code on the server, exploit requires hosting D-Tale publicly.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

dtale

Published Date

August 4, 2026

Template Author

0x_akoko

CVE-2024-55890.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-55890
CWE ID:
cwe-95

References

https://github.com/man-group/dtale/security/advisories/GHSA-qx2x-gvj9-gxw2https://nvd.nist.gov/vuln/detail/CVE-2024-55890

Remediation Steps

Upgrade to version 3.16.1 where the `update-settings` endpoint blocks `enable_custom_filters` updates.