CVE-2025-12763
Command injection vulnerability allowing arbitrary command execution on Windows
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
| Vendor | pgadmin.org |
| Product | pgadmin 4 |
| Published | Nov 13, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for pgadmin.org pgadmin 4
Be the first to know when new medium vulnerabilities affecting pgadmin.org pgadmin 4 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
pgadmin.org / pgAdmin 4
0 โค 9.9