Back

CRITICAL

pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment

Published Apr 3, 2025

Description

Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules).

The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is unsafely passed to the Python eval() function, allowing arbitrary code execution.

This issue affects pgAdmin 4: before 9.2.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PostgreSQL
Published Apr 3, 2025
Updated Feb 26, 2026
Reserved Mar 29, 2025
CISA Vulnrichment
Updated Apr 4, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner PostgreSQL
Published Apr 3, 2025
Updated Feb 26, 2026
Exploited since n/a
EUVD-2025-9605 GHSA-G73C-FW68-PWX3