CVE-2025-12762 PUBLISHED

Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)

Assigner: PostgreSQL
Reserved: 05.11.2025 Published: 13.11.2025 Updated: 01.12.2025

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the integrity and security of the database management system and underlying data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
CVSS Score: 9.1

Product Status

Vendor pgadmin.org
Product pgAdmin 4
Versions Default: unaffected
  • affected from 0 to 9.9 (incl.)

References