pgAdmin 4 Command Injection Vulnerability on Windows Systems

Vulnerability

A command injection vulnerability has been identified in pgAdmin 4, affecting versions prior to 9.9, on Windows platforms. The issue arises from the use of 'shell=True' during backup and restore processes, which allows attackers to execute arbitrary system commands by crafting specific file path inputs.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of system commands, potentially allowing an attacker to manipulate the system or application in harmful ways.

Remediation

Users can update to pgAdmin 4 version 9.10 or later, where this vulnerability has been fixed.

Added: Nov 13, 2025, 1:22 PM
Updated: Nov 13, 2025, 1:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
10.0
exploitability
5.8
remediation
7.7
relevance
1.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.