CVE-2024-1713: PLV8

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during autovacuum.

Affected products

  • PLV8 PLV8: version 3.2.1 only

Published 2024-03-14. Last modified 2026-06-17.