Medium severity6.8NVD Advisory· Published Nov 13, 2025· Updated Jun 17, 2026
CVE-2025-12763
CVE-2025-12763
Description
pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pgadmin4PyPI | < 9.10 | 9.10 |
Affected products
4cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*+ 1 more
- cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:*range: <9.10
- (no CPE)range: 0
- ghsa-coords2 versions
< 9.10+ 1 more
- (no CPE)range: < 9.10
- (no CPE)range: < 9.11-1.1
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-rm79-x4g6-hvg5ghsaADVISORY
- github.com/pgadmin-org/pgadmin4/issues/9323nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-12763ghsaADVISORY
- github.com/pgadmin-org/pgadmin4/commit/e374edc69239b3e02ecde895e27d9f9e488b87eeghsaWEB
News mentions
0No linked articles in our index yet.