← Vulnerability feed

Vulnerability record · CVE-2024-3408 · published 6 June 2024

CVE-2024-3408: D-Tale hardcoded SECRET_KEY enables auth bypass and RCE

Man · D Tale

man-group/dtale 3.10.0 ships a hardcoded Flask SECRET_KEY, letting attackers forge session cookies when authentication is enabled. The same release fails to restrict custom filter queries, so the /update-settings endpoint can be abused to run arbitrary code even when enable_custom_filters is off. Both flaws combine into full authentication bypass and remote code execution.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-798 · Hard-coded credentialsCWE-94 · Code injection
9.8CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint, even when `enable_custom_filters` is not enabled. This vulnerability allows attackers to bypass authentication mechanisms and execute remote code on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no privileges or interaction required, public exploit reference, and very high EPSS make this an urgent patch-first issue.

What it is

man-group/dtale 3.10.0 ships a hardcoded Flask SECRET_KEY, letting attackers forge session cookies when authentication is enabled. The same release fails to restrict custom filter queries, so the /update-settings endpoint can be abused to run arbitrary code even when enable_custom_filters is off. Both flaws combine into full authentication bypass and remote code execution.

Impact

An unauthenticated attacker can forge a valid session, bypass login, and execute arbitrary code on the server, gaining full control of the host and any data it can reach.

Attack surface

Reached over the network via the Flask web interface; the CVSS vector shows no privileges or user interaction required, and the description states the cookie forgery applies when authentication is enabled while the filter bypass works regardless of the enable_custom_filters setting.

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.77951 (99.55th percentile) and a public Huntr exploit reference exists, indicating high likelihood of active exploitation.

What to do

  • Upgrade dtale past 3.10.0 using the fix commit 32bd6fb4a63de779ff1e51823a456865ea3cbd13 or a later release.
  • Replace the hardcoded SECRET_KEY with a unique, randomly generated value per deployment and rotate any existing sessions.
  • Disable or restrict the /update-settings endpoint and custom filter functionality until patched.
  • Do not expose dtale directly to untrusted networks; place it behind authentication and network controls.
  • Monitor for forged session cookies and unexpected code execution on dtale hosts.

Detection

  • Inspect Flask session cookies for signatures that validate against the default hardcoded SECRET_KEY.
  • Alert on POST requests to /update-settings, especially with custom filter payloads.
  • Monitor dtale processes for unexpected child processes or outbound connections indicating code execution.
  • Review web logs for authentication bypass patterns such as valid sessions without a prior login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3408 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-45595Man d-tale cross-site scripting vulnerabilityD-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run…EPSS 0.78%9.8CVE-2023-46134Man d-tale cross-site scripting vulnerabilityD-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to version 3.7.0, users hosting D…EPSS 0.76%8.1CVE-2026-27194Man d-tale injection vulnerabilityD-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter e…EPSS 0.96%7.5CVE-2024-21642Man d-tale server-side request forgery (ssrf) vulnerabilityD-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request for…EPSS 0.71%5.3CVE-2026-35052Man d-tale cross-site scripting vulnerabilityD-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale p…EPSS 0.86%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed

Source: NIST National Vulnerability Database (record CVE-2024-3408), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.