CVE-2025-12762

Published Nov 13, 2025

Last updated 8 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-12762 is a Remote Code Execution (RCE) vulnerability affecting pgAdmin versions up to 9.9. The vulnerability occurs when pgAdmin is running in server mode and performing restores from PLAIN-format dump files. This vulnerability allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin. Successful exploitation could compromise the integrity and security of the database management system and the underlying data.

Description
pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the integrity and security of the database management system and underlying data.
Source
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
NVD status
Analyzed
Products
pgadmin_4

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. CVE-2025-12762 - Critical RCE in pgAdmin up to v9.9. Attackers can execute arbitrary commands via crafted PLAIN-format dump files. CVSS 9.1. No patch available yet; mitigate immediately. #CVE #pgAdmin #infosec #database #SQL - More: https://t.co/Kw2VVrEU2g

    @HugoValters

    22 May 2026

    264 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #VulnerabilityReport #CommandInjection Critical pgAdmin Flaws (CVE-2025-12762, CVSS 9.1) Allow Remote Code Execution via PostgreSQL Dump Files https://t.co/ckAj78WHrz

    @Komodosec

    22 Dec 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. in november, i reported an RCE that bypassed the patch for CVE-2025-12762 in versions 9.10 of pgadmin4. it has now been patched in the latest release 9.11 and tracked as CVE-2025-13780 https://t.co/o8fxY6XKYO

    @zer0pwn

    11 Dec 2025

    477 Impressions

    0 Retweets

    7 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. 🚨 A new pgAdmin4 vulnerability, CVE-2025-12762 (CVSS 9.8), allows for RCE in server mode when restoring PLAIN-format dump files. This flaw carries the potential for full system compromise. 🔴 We detect 7,393 instances of potentially exposed hosts at time of writing. 🔴 Ve

    @censysio

    5 Dec 2025

    14570 Impressions

    36 Retweets

    217 Likes

    88 Bookmarks

    2 Replies

    0 Quotes

  5. 🚨 A new pgAdmin4 vulnerability, CVE-2025-12762 (CVSS 9.8), allows for RCE in server mode when restoring PLAIN-format dump files. This flaw carries the potential for full system compromise. 🔴 We observe 14,466 potentially vulnerable instances at time of writing. 🔴 Versio

    @censysio

    4 Dec 2025

    862 Impressions

    4 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️Vulnerabilidad en pgAdmin ❗CVE-2025-12762 ➡️Más info: https://t.co/OEgRtPrwyc https://t.co/DeEcauXAbj

    @CERTpy

    28 Nov 2025

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨Upozorňujeme na kritickou RCE zranitelnost v pgAdmin, CVE-2025-12762. Pokud aplikace pracuje v režimu server, pak se v ní nachází chyba zabezpečení, kdy při provádění operací obnovení používá výpisové soubory PostgreSQL ve formátu PLAIN. Útočníci mohou v

    @GOVCERT_CZ

    21 Nov 2025

    267 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. pgAdminに深刻な脆弱性4件(CVE-2025-12762, CVSS 9.1)など https://t.co/wo9bLhFa7Q #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    20 Nov 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🔴 pgAdmin, Remote Code Execution, #CVE-2025-12762 (Critical) https://t.co/dxPumYx47W

    @dailycve

    19 Nov 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. #poc 🎯 CVE-2025-12762 exposes systems running pgAdmin in server mode to remote code execution #pgAdmin #PostgreSQL https://t.co/dyMuZnMYom

    @absholi7ly

    18 Nov 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨🚨CVE-2025-12762 (CVSS 9.1): Critical pgAdmin4 RCE pgAdmin4 server mode + plain backup restore = instant RCE Search by vul.cve Filter👉vul.cve="CVE-2025-12762" ZoomEye Dork👉app="pgAdmin4" 40.3k+ exposed instances ZoomEye Link: https://t.co/l7ZKnjpObB Refer: 1. h

    @zoomeye_team

    17 Nov 2025

    5763 Impressions

    23 Retweets

    74 Likes

    37 Bookmarks

    1 Reply

    0 Quotes

  12. 🚨Alert🚨:CVE-2025-12762 : Critical pgAdmin Flaws Allow Remote Code Execution via PostgreSQL Dump Files. It affects versions up to 9.9. 📊188.5K Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:https://t.co/H4H1mAx3qg 👇Query HUNTER : https://t.co

    @HunterMapping

    17 Nov 2025

    3405 Impressions

    20 Retweets

    61 Likes

    29 Bookmarks

    0 Replies

    0 Quotes

  13. ⚠️ Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers Read more: https://t.co/OlfREXflVU A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases. Dubbed CVE-2025-12762,

    @The_Cyber_News

    17 Nov 2025

    4403 Impressions

    31 Retweets

    89 Likes

    22 Bookmarks

    0 Replies

    2 Quotes

  14. pgAdmin patched four flaws. The Critical RCE (CVE-2025-12762) risks arbitrary code execution via malicious PostgreSQL dump files. LDAP Injection (CVE-2025-12764) and TLS Bypass were also fixed. Update to v9.10. #pgAdmin #RCE #Cybersecurity #PostgreSQL https://t.co/2smCTmL72d

    @Daily_CyberSec

    17 Nov 2025

    24 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2025-12762 - Exploit and Reproduction for pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server mode #pruva reproduction: https://t.co/rt2E1Cf7kN Advs: https://t.co/PQsGAMMpCU

    @N3mes1s

    14 Nov 2025

    4069 Impressions

    15 Retweets

    55 Likes

    27 Bookmarks

    1 Reply

    0 Quotes

  16. 🚨 pgAdmin < 9.10 has an RCE vulnerability (CVE-2025-12762) allowing attackers to execute arbitrary commands on the server, risking the database system's integrity and security. https://t.co/4S73FCs7tI https://t.co/MNR03JdEds

    @IntCyberDigest

    14 Nov 2025

    7873 Impressions

    23 Retweets

    64 Likes

    20 Bookmarks

    0 Replies

    1 Quote

  17. CVE-2025-12762 pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-form… https://t.co/MqbRbvmUM6

    @CVEnew

    13 Nov 2025

    145 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. [CVE-2025-12762: CRITICAL] Critical Remote Code Execution (RCE) vulnerability in pgAdmin versions up to 9.9 allows attackers to execute arbitrary commands, posing a severe threat to cyber security.#cve,CVE-2025-12762,#cybersecurity https://t.co/qhfmldF6k4 https://t.co/iyNLblD59Y

    @CveFindCom

    13 Nov 2025

    57 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  19. CVE-2025-12762 is a critical pgAdmin 4 RCE (CVSS 9.1) affecting versions ≤9.9. Network-accessible, low complexity, requires only low privs. The Changed Scope (S:C) rating means compromise extends beyond pgAdmin itself. Attack surface: Restore module processing PLAIN-format

    @gothburz

    13 Nov 2025

    619 Impressions

    1 Retweet

    7 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  20. **CVE-2025-12762** is a critical Remote Code Execution (RCE) vulnerability affecting **pgAdmin** versions up to 9.9. when operating in server mode, specifically during the restore process from PLAIN-format dump files. The vulnerability allows an attacker to inject malicious

    @CveTodo

    13 Nov 2025

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

  1. Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through html-react-parser at every user-facing sink — the notifier toasts, FormFooterMessage / FormInput help and error areas, FormNote, ModalProvider AlertContent and confirmDelete, ToolErrorView, the Explain visualiser's NodeText panel, the SQL editor confirm dialogs, ConfirmSaveContent, PreferencesHelper modal alerts, and SelectThemes helper text. A PostgreSQL server an attacker controls — or any server returning attacker-influenced text such as a table or column name a low-privilege database user can create — could inject arbitrary HTML (including <iframe>) into the pgAdmin DOM the moment the victim's pgAdmin connected to that server or viewed an Explain plan that referenced the crafted object. The injected iframe's srcdoc could fetch attacker-served JavaScript and, by writing to parent.location, redirect the victim's top-level pgAdmin browser tab to an attacker-controlled URL. Because the injection originates from inside pgAdmin's own interface, standard anti-clickjacking controls (X-Frame-Options, Content-Security-Policy: frame-ancestors) do not mitigate it. A phishing page rendered inside the legitimate pgAdmin window is indistinguishable from a genuine pgAdmin dialog. Fix combines three complementary layers. (1) DOMPurify sanitisation is wrapped around every html-react-parser call site reachable from notifier, alert, form-error, Explain, and SQL-editor flows. (2) A new plain-text rendering contract — SafeMessage / SafeHtmlMessage components plus Notifier.errorText / alertText / warningText / infoText / successText helpers — is introduced; around fifty callers across browser, tools, dashboard, debugger, misc, llm, preferences, schema diff, and the SQL editor that previously interpolated backend-derived strings are migrated to the plain-text variants. (3) Backend HTML-escape is applied at the post-connection-SQL handler (execute_post_connection_sql) via a new sanitize_external_text helper, so third-party JSON consumers (audit logs, API clients) never receive raw markup either; the Explain plan-info renderer is also patched to _.escape Recheck Cond and Exact Heap Blocks at construction (matching every sibling field), giving defence in depth even before DOMPurify runs. This issue affects pgAdmin 4: from 6.0 before 9.16.CVE-2026-12048
  2. HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception text — and the related file-resolution and database-commit exception text — into the JSON response body (the info and errormsg fields) without HTML-encoding. The Cloud Wizard frontend rendered these strings through html-react-parser, so an attacker-influenced exception message embedded structural HTML directly into the wizard's DOM. The reported entry point is /rds/verify_credentials/. An authenticated pgAdmin user submits a crafted access_key whose value contains an <iframe/src=...> payload; AWS STS rejects the credential with an IncompleteSignature exception whose text quotes the access_key verbatim; the pgAdmin backend forwards that text into the JSON info field; the Cloud Wizard's FormFooterMessage parses it as HTML. The browser fetches the iframe's src from an attacker-controlled host, and JavaScript executing inside the cross-origin iframe writes to parent.location, redirecting the victim's pgAdmin tab. Because the injection renders inside pgAdmin's own interface, X-Frame-Options and Content-Security-Policy frame-ancestors do not mitigate it. Baseline impact is self-targeted (the same user who supplied the payload sees the injection); escalation against other authenticated users requires an additional cross-site request-forgery primitive capable of submitting the malformed credential request with a valid X-pgA-CSRFToken in the victim's browser context. The same unsanitised-error-into-JSON pattern was present across multiple sibling endpoints — Azure's check_cluster_name_availability, every Google endpoint that surfaces SDK errors (verification_ack, projects, regions, instance_types, database_versions, the verify_credentials path-resolution branches), the central /deploy endpoint that bubbles str(e) from deploy_on_rds / deploy_on_azure / deploy_on_google, and update_cloud_server which surfaces the str(e) from a failing db.session.commit — all of which are now covered. Fix HTML-escapes every external/SDK exception string at the endpoint sink via a new shared sanitize_external_text helper (HTML escape with control-character strip), promoted out of the psycopg3 driver into web/pgadmin/utils/text_sanitize.py. The Cloud Wizard frontend additionally renders its FormFooterMessage in plain-text mode for backend-derived strings, so the value is never parsed as HTML even if a future sink forgets the escape. This issue affects pgAdmin 4: from 6.6 before 9.16.CVE-2026-12047
  3. Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only routes in the module missing the @pga_login_required decorator. Both reach a pickle.loads sink on session['gridData'][<trans_id>]['command_obj']: the close endpoint via close_sqleditor_session(), and update_sqleditor_connection via check_transaction_status(). In server mode these endpoints were reachable without any authenticated pgAdmin session. The defect is a missing-authentication-on-critical-function (CWE-306) wrapper around a deserialization-of-untrusted-data sink (CWE-502). Exploiting it for remote code execution requires the attacker to also forge a server-side session file whose gridData entry contains a malicious pickle payload, which in turn requires both (a) knowledge of pgAdmin's Flask SECRET_KEY (no chain to leak it is described here -- the attacker must already possess it) and (b) write access to pgAdmin's sessions/ directory on the host. Neither precondition is granted by this defect on its own. When those preconditions are met from another channel (misconfigured deployment, prior compromise, leaked configuration), the missing auth gate is the final hop that turns an existing partial compromise into unauthenticated code execution in the pgAdmin process -- and, by extension, on the host under whatever account runs pgAdmin. Fix is a one-line @pga_login_required decorator on each of the two endpoints, matching the convention used by every other route in the module. The is_authenticated / MFA chain now runs before the trans_id is dereferenced, so an unauthenticated request is rejected before reaching the deserialization path. The defect is server-mode only. In DESKTOP mode pgAdmin's before_request hook re-authenticates DESKTOP_USER on every request, so no endpoint can be exercised in an unauthenticated state and no auth decorator (or its absence) is meaningful. The accompanying regression test mirrors the attacker's path -- harvests an X-pgA-CSRFToken from GET /login and replays it against both endpoints -- and self-skips outside server mode for that reason; it is wired into the existing server-mode CI workflow alongside the data-isolation tests. This issue affects pgAdmin 4: from 6.9 before 9.16.CVE-2026-12046

References

Sources include official advisories and independent security research.