logo

Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi

ID: 51a0e985-712b-5566-ad0d-b78dff527629

STIX ID: report--51a0e985-712b-5566-ad0d-b78dff527629

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Do Son

...
...

pgAdmin 4 has three critical vulnerabilities (CVSSv4 scores 9.3–9.5) affecting error/plan-node rendering (stored XSS), SQL Editor endpoints (unauthenticated pickle deserialization leading to potential RCE), and the AI Assistant (read-only transaction bypass enabling unauthorized writes and possible command execution); all are fixed in release 9.16 and no active exploitation has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.