Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi
ID: 51a0e985-712b-5566-ad0d-b78dff527629
STIX ID: report--51a0e985-712b-5566-ad0d-b78dff527629
Feed Name: securityonline.info
Threat Score
pgAdmin 4 has three critical vulnerabilities (CVSSv4 scores 9.3–9.5) affecting error/plan-node rendering (stored XSS), SQL Editor endpoints (unauthenticated pickle deserialization leading to potential RCE), and the AI Assistant (read-only transaction bypass enabling unauthorized writes and possible command execution); all are fixed in release 9.16 and no active exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
