A critical flaw in StackGres allowed a low-privilege tenant who owns a PostgreSQL database to escalate to remote code execution in the primary PostgreSQL pod through the platform’s default metrics exporter. The issue was reported by Cipher of Causal Security and tracked in GitLab as a tenant DB-owner to pod RCE path affecting StackGres 1.x through 1.18.8 and the referenced 1.19.0-SNAPSHOT build. According to the report, the exporter connected as the cluster superuser and, during Prometheus scrapes, opened superuser dblink sessions into tenant databases.
The exploit relied on the exporter executing remote SQL with unqualified object references while failing to pin search_path, allowing an attacker to set a database-level search_path and create shadow objects such as a malicious version() function. When the exporter’s superuser session resolved those objects, it could be driven into attacker-controlled execution and ultimately reach PostgreSQL primitives such as COPY ... TO PROGRAM for operating-system command execution inside the pod. The vulnerability was later discussed as fixed and released in StackGres 1.19.0 GA, and a CVE request was subsequently submitted through GitLab’s process.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The report states that the per-database superuser dblink fan-out behavior in StackGres has existed since 2024-01, creating the conditions for later exploitation via unpinned search_path handling in metrics exporter queries.
After the fix was released in StackGres 1.19.0 GA, a CVE ID request was created through GitLab's process for the vulnerability.
The GitLab issue discussion indicates that a fix for the vulnerability was merged and later released in StackGres 1.19.0 GA, making that release the first stated fixed version.
Cipher of Causal Security reported a critical vulnerability in StackGres through a GitLab issue. The issue describes how a low-privilege tenant who owns a PostgreSQL database can achieve remote code execution in the primary PostgreSQL pod via the default metrics exporter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.