PT-2026-39626 · Pgadmin 4+2 · Pgadmin 4+2
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions prior to 9.15
Description
An OS command injection issue exists in the Import/Export query export feature. Authenticated users can exploit this by providing unsanitized input that is interpolated directly into a psql
copy metacommand template. This allows an attacker to break out of the command context to execute arbitrary commands on the pgAdmin server or perform arbitrary file writes. Additionally, the format, on error, and log verbosity fields are susceptible to raw interpolation and exploitation.Recommendations
Update to version 9.15 or later.
Restrict access to the Import/Export query export feature for authenticated users until the update is applied.
Exploit
Fix
SQL injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin
Red Os
Pgadmin 4