PT-2026-94388 · Pgadmin · Pgadmin
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions prior to 9.18
Description
The
save file endpoint in the File Manager, used by the Query Tool and ERD, contains a race condition. While the system validates the requested path using the check access permission() function, it subsequently uses a plain open() call to write the file. An attacker with filesystem access to the host or a shared storage backend could substitute a symbolic link at the final path component between the validation check and the write operation. This would allow the application to follow the link and create or overwrite an arbitrary file outside the user's storage directory with the privileges of the operating-system account running the software.Recommendations
Update pgAdmin 4 to version 9.18 or later.
Exploit
Fix
DoS
Link Following
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin