pgAdmin 4 developers released security updates for two critical vulnerabilities affecting versions earlier than 9.2, including CVE-2025-2945 and CVE-2025-2946. The most severe issue, CVE-2025-2945 (CVSS 9.9), is a remote code execution flaw in the Query Tool and Cloud Deployment components caused by unsafe use of Python eval() on unsanitized POST parameters, allowing an authenticated remote attacker to compromise confidentiality, integrity, and availability.
The second flaw, CVE-2025-2946 (CVSS 9.1), is a cross-site scripting vulnerability in the Query Tool and View/Edit Data components that can execute attacker-controlled HTML or JavaScript when query results are rendered in the result grid. Public proof-of-concept exploit code is available for the vulnerabilities, increasing exploitation risk, and users are being urged to upgrade pgAdmin 4 to version 9.2 or later immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that pgAdmin 4 developers released security updates fixing two critical vulnerabilities affecting versions older than 9.2. Users were advised to upgrade to version 9.2 or later, and the report noted that proof-of-concept exploit code was publicly available.
Two GitHub issues documenting critical pgAdmin 4 vulnerabilities were published: CVE-2025-2946 covering an XSS flaw in the Query Tool and View/Edit Data components, and CVE-2025-2945 covering a remote code execution flaw in the Query Tool and Cloud Deployment components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.