CVE-2024-3408 affects man-group/dtale 3.10.0. A hardcoded Flask secret key permits forging session cookies where authentication is enabled. Separately, inadequate validation and restriction of custom filter queries permits arbitrary server-side code execution through the application’s settings-update functionality, including when custom filters are disabled. The flaws enable authentication bypass and remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a reproducible lab environment and proof-of-concept exploit for CVE-2024-3408, a critical authentication bypass and remote code execution (RCE) vulnerability in D-Tale (<= 3.15.1). The vulnerability arises from a hardcoded Flask SECRET_KEY, allowing attackers to forge session cookies, and from unsafe use of pandas query filters, which can be abused for arbitrary code execution. The repository includes: - A Dockerfile and docker-compose.yml to build and run a vulnerable D-Tale 3.10.0 instance on port 40000. - A Bash script (scripts/poc.sh) that automates the exploitation process: it first enables custom filters via a crafted HTTP request, then injects a malicious pandas query to execute arbitrary OS commands (demonstrated with 'id'). - A Python script (start.py) that launches D-Tale with sample data for testing. The main exploit capability is remote code execution via a network attack vector, targeting the '/dtale/test-filter/1' endpoint after enabling custom filters. The exploit is a working proof-of-concept and demonstrates the vulnerability in a controlled environment. No fake or detection-only scripts are present; the code is a functional exploit.
This repository contains a single Metasploit module (modules/exploits/linux/http/dtale_rce_cve_2025_0655.rb) targeting D-Tale, a Python web application for visualizing pandas data structures. The exploit leverages a vulnerability (CVE-2025-0655, also referencing CVE-2024-3408) that allows an attacker to bypass authentication and enable the 'enable_custom_filters' feature, which is normally restricted. Once enabled, the attacker can use the /dtale/test-filter endpoint to execute arbitrary system commands via crafted input. The module is weaponized, supporting customizable payloads (defaulting to a Meterpreter reverse shell) and is fully integrated into the Metasploit framework. The attack is performed over HTTP, requiring only network access to the vulnerable D-Tale instance. The module includes routines for checking vulnerability, exploitation, and cleanup. All endpoints are accessed via HTTP requests, and the exploit is effective against D-Tale versions up to and including 3.15.1 on Linux.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical authentication-bypass and remote-code-execution vulnerability in man-group/dtale 3.10.0. Attackers can forge authenticated session cookies using a hardcoded Flask SECRET_KEY and execute arbitrary code by bypassing custom-filter restrictions on the /update-settings endpoint, including when custom filters are disabled.
A remote code execution vulnerability in D-Tale, allowing attackers to execute arbitrary code on the affected system.
A vulnerability in D-Tale (CVE-2024-3408) allows authentication bypass and remote code execution (RCE), enabling attackers to gain unauthorized access and execute arbitrary code.
A critical vulnerability in D-Tale (CVE-2024-3408) allows for authentication bypass and remote code execution, enabling attackers to gain unauthorized access and execute arbitrary code on affected systems.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.