CVE-2025-12762: Remote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the integrity and security of the database management system and underlying data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12762?
CVE-2025-12762 is classified as a Remote Code Execution vulnerability, which is considered highly severe.
How do I fix CVE-2025-12762?
To remediate CVE-2025-12762, upgrade to pgAdmin version 10.0 or later.
What versions of pgAdmin are affected by CVE-2025-12762?
CVE-2025-12762 impacts all pgAdmin versions up to and including 9.9.
What type of vulnerability is CVE-2025-12762?
CVE-2025-12762 is a Remote Code Execution vulnerability.
Can CVE-2025-12762 be exploited remotely?
Yes, CVE-2025-12762 can be exploited remotely when pgAdmin is running in server mode and performing restores from PLAIN-format dump files.