Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.1epss 12%
from disclosure to weapon11 days
Published on NVDNov 13
1st PoC+11d
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the integrity and security of the database management system and underlying data.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Affected products
pgadmin.org · pgAdmin 4public PoCs found — 1
githubgithub.com/djayaGit/Blackash-CVE-2025-12762★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.