Executive brief
pgAdmin 4 is a popular management tool for PostgreSQL databases. A security vulnerability in its Import/Export feature allows an authorized user to execute unauthorized commands or write files on the server hosting the application. This could lead to a full system compromise, data theft, or disruption of operations.
Technical details
An OS command injection (CWE-78) exists in pgAdmin 4 due to improper sanitization of user-supplied input before it is interpolated into a psql \copy metacommand template. An authenticated attacker can provide a crafted query containing ") TO PROGRAM 'cmd'" to break out of the command context and execute arbitrary shell commands or write to local files. Other fields including format, on_error, and log_verbosity were also found to be vulnerable to raw interpolation. The vulnerability is fixed in version 9.15 by implementing a parenthesis-balancing parser, allow-listing specific fields, and rejecting null bytes.
Affected products
- PostgreSQL pgAdmin 4 9.4 to < 9.15
Timeline
- 2026-05-01: disclosed: Issue reported on GitHub
- 2026-05-11: advisory: CVE published and NVD entry created
- 2026-05-11: patched: Fixed in version 9.15