Dash is a lightweight Python framework and component library for building interactive web dashboards and analytical applications. Its vulnerability profile centers on web-application security boundaries, with the durable signal appearing in cross-site request forgery and OS command injection weaknesses that reflect input-validation and state-management risks in its request-handling and component-rendering architecture. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dash over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0854MEDIUM Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working | Mar 11, 2009 | 6.9 | 18 | NO | NO |
CVE-2019-16752MEDIUM An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on t | Dec 4, 2019 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dash.
Media articles that mention a CVE ID that affects a product developed by Dash — matched by CVE ID, not by vendor name.