CVE-2025-2945 Information

Description

Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules).

The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download where the query_commited parameter and /cloud/deploy endpoint where the high_availability parameter is unsafely passed to the Python eval() function allowing arbitrary code execution.

This issue affects pgAdmin 4: before 9.2.

Reference

https://github.com/pgadmin-org/pgadmin4/issues/8603

Share on: