CVE-2025-2945
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is unsafely passed to the Python eval() function, allowing arbitrary code execution. This issue affects pgAdmin 4: before 9.2.
Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is unsafely passed to the Python eval() function, allowing arbitrary code execution. This issue affects pgAdmin 4: before 9.2.
These are all security issues fixed in the pgadmin4-9.2-1.1 package on the GA media of openSUSE Tumbleweed.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-03-29 CVE Reserved
- 2025-04-03 CVE Published
- 2025-04-04 CVE Updated
- 2025-04-11 First Exploit
- 2025-06-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/pgadmin-org/pgadmin4/issues/8603 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/190447 | 2025-04-11 | |
https://github.com/abrewer251/CVE-2025-2945_PoC | 2025-06-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pgadmin.org Search vendor "Pgadmin.org" | PgAdmin 4 Search vendor "Pgadmin.org" for product "PgAdmin 4" | < 9.2 Search vendor "Pgadmin.org" for product "PgAdmin 4" and version " < 9.2" | en |
Affected
|