CVE-2025-31480: aiven-extras allows PostgreSQL Privilege Escalation through format function
aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should install 1.1.16 and ensure they run the latest version issuing ALTER EXTENSION aivenextras UPDATE TO '1.1.16' after installing it. This needs to happen in each database aivenextras has been installed in.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31480?
CVE-2025-31480 is classified as a privilege escalation vulnerability that could allow attackers to gain superuser access to PostgreSQL databases.
How do I fix CVE-2025-31480?
To mitigate CVE-2025-31480, users should upgrade to aiven-extras version 1.1.16 or later.
What systems are affected by CVE-2025-31480?
CVE-2025-31480 affects PostgreSQL databases using the aiven-extras extension up to version 1.1.16.
What is the impact of exploiting CVE-2025-31480?
Exploiting CVE-2025-31480 can allow an attacker to elevate their privileges to superuser within the PostgreSQL database.
How can I determine if I'm using a vulnerable version related to CVE-2025-31480?
Check the version of the aiven-extras extension installed on your PostgreSQL database and verify if it is below 1.1.16.