Hmm, all these eval() calls using data from cookies[0]... is this vulnerable to remote code execution? I think those eval() calls should be json.loads().
[0] https://github.com/k3oni/pydash/blob/1317771275aa118a40df1ec...
[0] https://github.com/k3oni/pydash/blob/1317771275aa118a40df1ec...
The data in the cookies is just JSON, right? If json.loads() would work here you should switch to that instead.
I would hope that people won't give access to everyone to the dashboard, wasn't really build for that, or at least that wasn't my initial idea.