High severity7.5NVD Advisory· Published Jan 5, 2024· Updated Jun 17, 2026
CVE-2024-21642
CVE-2024-21642
Description
D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing attackers to access files on the server. Users should upgrade to version 3.9.0, where the Load From the Web input is turned off by default. The only workaround for versions earlier than 3.9.0 is to only host D-Tale to trusted users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dtalePyPI | < 3.9.0 | 3.9.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/man-group/dtale/commit/954f6be1a06ff8629ead2c85c6e3f8e2196b3df2nvdPatchWEB
- github.com/man-group/dtale/security/advisories/GHSA-7hfx-h3j3-rwq4nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-7hfx-h3j3-rwq4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-21642ghsaADVISORY
News mentions
0No linked articles in our index yet.