A critical remote code execution vulnerability, tracked as CVE-2025-13780, was discovered in pgAdmin 4, the widely used open-source PostgreSQL database management tool. The flaw allows attackers to bypass security filters in the plain-text restore feature by inserting unexpected whitespace characters, enabling the execution of arbitrary shell commands on the host server through maliciously crafted SQL dump files. The vulnerability affects pgAdmin 4 versions prior to 9.11 and was found to stem from an inadequate regular expression filter that failed to block dangerous commands effectively.
Security researchers at EndorLabs identified the issue and reported that attackers could exploit this weakness to gain unauthorized access and potentially take over affected servers. In response, the pgAdmin development team released version 9.11, which implements the \restrict command to disable hazardous operations during the restore process, fundamentally improving the security model by enforcing restrictions at the execution level rather than relying solely on input filtering. Users are strongly advised to update to the latest version to mitigate the risk of exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Security reports publicly disclosed CVE-2025-13780 as a critical pgAdmin vulnerability that bypassed an earlier fix and enabled server takeover through malicious database restore input. The disclosure emphasized the severity of the flaw, including a reported CVSS score of 9.9.
Following the discovery, the pgAdmin team released version 9.11 to mitigate the vulnerability by using the \restrict command at the execution layer instead of relying on regex-based input filtering. Administrators were advised to upgrade because older versions remained exposed.
Researchers identified a critical remote code execution flaw in pgAdmin 4 that let attackers bypass prior security filters in the plain-text restore feature using crafted SQL dump files. The issue could lead to arbitrary shell command execution and full server compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.