CVE-2025-12763
EUVD-2025-16929513.11.2025, 13:15
pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pgadmin | pgadmin_4 | 𝑥 < 9.10 |
𝑥
= Vulnerable software versions