# GHSA-c87c-78rc-vmv2: D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

**Severity:** HIGH | **Source:** ghsa

## Description

### Impact
Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server.

### Patches
Users should upgrade to version 3.20.0.

### Workarounds
There are no workarounds for versions < 3.20.0

## Weakness

- [CWE-74](https://cwe.mitre.org/data/definitions/74.html)

## Affected Packages

### dtale (pip)
- **Vulnerable:** `< 3.20.0`
- **Fixed in:** `3.20.0`

## References

**Commits:**
- https://github.com/man-group/dtale/commit/431c6148d3c799de20e1dec86c4432f48e3d0746

**Advisories:**
- https://github.com/man-group/dtale/security/advisories/GHSA-c87c-78rc-vmv2
- https://github.com/advisories/GHSA-c87c-78rc-vmv2

## Related Identifiers

- CVE-2026-27194

---

**Source:** https://github.com/advisories/GHSA-c87c-78rc-vmv2
**Published:** 2026-02-19
**Ingested:** 2026-02-20 14:36:48 UTC

## Reproduction Steps

_To be determined by the reproduction agent._
