CVE-2025-12763: Pgadmin 4
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
Affected products
- Pgadmin Pgadmin 4: before 9.10 (fixed in 9.10)
Published 2025-11-13. Last modified 2026-10-07.