Vendor
D-Tale versions 3.15.1 and earlier are vulnerable to unauthenticated remote code execution due to a hardcoded Flask secret key and unsafe pandas query evaluation.