dtale

condav3.22.0

D-Tale is the combination of a Flask back-end and a React front-end to bring you an easy way to view & analyze Pandas data structures

License LGPL-2.1-only160 versions1 maintainers0 deps1,761 weekly dl
man-group/dtale/
63
/ 100
Health
do not use

dtale has critical vulnerabilities — do not use

Update to >= 32bd6fb4a63de779ff1e51823a456865ea3cbd13 to fix known vulnerabilities

  • 1 critical vulnerabilities
Health breakdown0 – 100
25/25
maintenance
6/20
popularity
15/25
security
15/15
maturity
2/15
community
Vulnerabilities
1
1 critical
Advisories (1)
SeverityIDSummaryFixed in
criticalCVE-2024-3408man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint,32bd6fb4a63de779ff1e51823a456865ea3cbd13
Threat intelligence
1 likely exploited (EPSS ≥ 0.5)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/conda/dtale

First published · 2020-05-31 14:48:59.449000+00:00

Last updated · 2026-04-01 13:43:46.846000+00:00