PT-2025-12319 · Man · D-Tale

Published

2025-03-20

·

Updated

2025-05-31

·

CVE-2025-0655

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions man-group/dtale version 3.15.1
Description A vulnerability in man-group/dtale allows an attacker to override global state settings to enable the enable custom filters feature, which is typically restricted to trusted environments. Once enabled, the attacker can exploit the "/test-filter" endpoint to execute arbitrary system commands, leading to remote code execution (RCE). This issue is addressed in version 3.16.1.
Recommendations Update to version 3.16.1 to fix the issue. As a temporary workaround, consider disabling the enable custom filters feature until a patch is available. Restrict access to the "/test-filter" endpoint to minimize the risk of exploitation. Avoid using the enable custom filters feature in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-0655
GHSA-GJXM-X497-4H6H

Affected Products

D-Tale