CVE-2026-35052

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/04/2026
Last modified:
20/04/2026

Description

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:man:d-tale:*:*:*:*:*:*:*:* 3.22.0 (excluding)