Get real-time updates on Telegram
CVE-2025-13780: pgadmin 4 through 9.10 (inclusive); +1 more affected products
CVE-2025-13780. CVSS 3.1 base score 8.8 (HIGH, NVD). EPSS 0.00943 (percentile 0.59748), scored 2026-10-06.
Affected technology
pgadmin 4 · through 9.10 (inclusive)
pgadmin
pgAdmin 4 · 0 through 9.10
pgadmin.org
Description’s affected range: versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files
Component: Restore
File: https://github.com/pgadmin-org/pgadmin4/blob/master/web/pgadmin/tools/restore/__init__.py
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could run code remotely under the conditions described by the source. Source advisory’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality impact as high; integrity and availability impact as low. NVD’s CVSS 3.1 assessment (base score 8.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-94
- CCR priority
- 35.4 /100 (P4)
- CVSS 3.1
- 8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.00943 · percentile 0.59748 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-13780.html