Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server.
Users should upgrade to version 3.20.0.
There are no workarounds for versions < 3.20.0
{
"github_reviewed_at": "2026-02-19T20:29:05Z",
"nvd_published_at": "2026-02-21T05:17:29Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-74"
],
"github_reviewed": true
}