PyPI: dash

CVE-2024-21485

Safety vulnerability ID: SFTY-20240202-24919

Safety legacy ID: pyup.io-65284

Earlier versions of Dash and its components are susceptible to an XSS vulnerability, specifically through the manipulation of the href attribute in a tags by an attacker. This flaw could potentially allow an authenticated attacker to access or manipulate user data and tokens, assuming the ability to store and present manipulated views to other users. The vulnerability notably requires the presence of user input storage mechanisms within Dash applications to be exploitable. Further details are covered under CVE-2024-21485. #Note: This is only exploitable in Dash apps that include some mechanism to store user input to be reloaded by a different user. See CVE-2024-21485.

Created at: May 22, 2026Updated at: May 22, 2026

Overview

Dash apps vulnerable to Cross-site Scripting

Advisory

Earlier versions of Dash and its components are susceptible to an XSS vulnerability, specifically through the manipulation of the href attribute in a tags by an attacker. This flaw could potentially allow an authenticated attacker to access or manipulate user data and tokens, assuming the ability to store and present manipulated views to other users. The vulnerability notably requires the presence of user input storage mechanisms within Dash applications to be exploitable. Further details are covered under CVE-2024-21485. #Note: This is only exploitable in Dash apps that include some mechanism to store user input to be reloaded by a different user. See CVE-2024-21485.

Affected Package

Affecting dash package, versions
<2.13.0
>=2.14.0,<2.15.0

Also affects

---

How to Fix

Upgrade
dash
to
2.13.0
2.15.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more