PyPI: dtale

CVE-2024-45595

Safety vulnerability ID: SFTY-20240910-51587

Safety legacy ID: pyup.io-73185

D-Tale affected versions potentially exposed a security vulnerability by processing user-supplied queries without restrictions. This could allow malicious actors to craft queries leading to unauthorized data access or manipulation. The patch introduces a feature flag, "enable_custom_filters", which, when disabled, prevents processing of custom queries, significantly reducing the attack surface. Users are advised to update to the latest version and carefully manage this new flag, enabling custom filters only when necessary. Organizations should review any existing deployments, ensure proper configuration of the feature flag, and consider disabling custom filters in sensitive environments.

Created at: May 22, 2026Updated at: May 22, 2026

Overview

D-Tale vulnerable to Remote Code Execution through the Query input on Chart Builder

Advisory

D-Tale affected versions potentially exposed a security vulnerability by processing user-supplied queries without restrictions. This could allow malicious actors to craft queries leading to unauthorized data access or manipulation. The patch introduces a feature flag, "enable_custom_filters", which, when disabled, prevents processing of custom queries, significantly reducing the attack surface. Users are advised to update to the latest version and carefully manage this new flag, enabling custom filters only when necessary. Organizations should review any existing deployments, ensure proper configuration of the feature flag, and consider disabling custom filters in sensitive environments.

Affected Package

Affecting dtale package, versions
<3.14.1

Also affects

---

How to Fix

Upgrade
dtale
to
3.14.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more