CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-13780: pgadmin 4 through 9.10 (inclusive); +1 more affected products

CVE-2025-13780. CVSS 3.1 base score 8.8 (HIGH, NVD). EPSS 0.00943 (percentile 0.59748), scored 2026-10-06.

Affected technology

pgadmin 4 · through 9.10 (inclusive)
pgadmin

pgAdmin 4 · 0 through 9.10
pgadmin.org

Description’s affected range: versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files

Component: Restore
File: https://github.com/pgadmin-org/pgadmin4/blob/master/web/pgadmin/tools/restore/__init__.py

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

Attack conditions (NVD, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run code remotely under the conditions described by the source. Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality impact as high; integrity and availability impact as low. NVD’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-94
CCR priority
35.4 /100 (P4)
CVSS 3.1
8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00943 · percentile 0.59748 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-13780.html