pgpartman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pgjobmon is installed and partconfig.jobmon is true, exception handlers in multiple pgpartman functions place pparenttable verbatim inside a SQL string literal used to call pgjobmon.addjob(). A partmanuser can create a parent-table name containing a single quote that terminates the literal and injects SQL when an affected exception path runs. If pgpartmanbgw reaches that path, the injected SQL executes with pgpartmanbgw.role privileges, which default to PostgreSQL superuser, permitting database-wide compromise and operating-system command execution as the PostgreSQL service account. The persistent partconfig row can trigger the escalation again on later maintenance ticks. This issue is fixed in version 5.5.0.