PT-2026-94391 · Pgadmin · Pgadmin
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pgAdmin 4 versions prior to 9.18
Description
The Backup tool in pgAdmin 4 fails to validate the
database field within the /backup/job/<sid>/object endpoint. This field is appended as a positional argument to the pg dump utility. Since pg dump uses getopt long for argument parsing, an attacker can provide a value starting with a dash to inject options. For example, using --file=/absolute/path allows the utility to write output to arbitrary locations accessible by the pgAdmin process, enabling arbitrary file creation and overwrite. Additionally, the database field allows connection-string injection because libpq expands names containing equals signs into full connection strings. This allows an attacker to redirect pg dump to a remote server, potentially leaking the decrypted database password stored in the PGPASSWORD environment variable. These actions can be performed by any authenticated user with tools backup permissions.Recommendations
Update pgAdmin 4 to version 9.18 or later.
Exploit
Fix
DoS
Path traversal
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgadmin