CVE-2025-12762 is a remote code execution vulnerability in pgAdmin affecting versions up to 9.9 when running in server mode and performing restores from PLAIN-format dump files. The flaw allows attacker-controlled content in a restore workflow to inject arbitrary commands that are executed on the host running pgAdmin. The issue is part of a class of command-injection flaws involving unsafe handling of psql meta-commands or COPY-related input during processing of PLAIN-format dump content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for authenticated remote code execution against pgAdmin 4 via CVE-2026-17566. The repo contains three files: an MIT LICENSE, a README describing the vulnerability and usage, and a single executable Python script, pgadmin4_rce_poc.py, which is the clear entry point. The exploit is not part of a larger framework. It uses Python standard-library networking only: urllib for HTTP(S), cookiejar for session handling, ssl for optional certificate verification bypass, regex for CSRF token extraction, and json for request construction. The script implements a complete attack flow: authenticate to pgAdmin, retrieve a CSRF token from GET /login, submit credentials to POST /login, enumerate accessible server objects via GET /browser/servers, then send a crafted JSON request to POST /import_export/job/<sid>. Its core capability is command execution on the host running pgAdmin. The malicious query is built by build_query(), which returns a payload of the form SELECT 'a\') TO PROGRAM '%s' x'. This is designed to exploit a parsing mismatch between pgAdmin's parenthesis checker and psql string handling, causing the injected TO PROGRAM clause to become active. The operator can supply an arbitrary command with --command or request an automatically generated bash reverse shell with --reverse HOST:PORT. Default demonstration behavior writes command output to /tmp/pgadmin_rce_proof, and the export job uses /tmp/pgadmin_export.csv as the nominal output file. Operationally, this is more than a detector: it performs authentication, target enumeration, payload generation, and exploit delivery. However, it is still a PoC-style standalone script rather than a weaponized framework module. The README also notes the code was based on public analysis and may require minor field adjustments depending on exact pgAdmin version behavior.
Repository contains a single Python proof-of-concept exploit script and a README. - Files: - CVE-2025-12762.py: Python exploit (requests-based) implementing an authenticated, network-delivered RCE chain against pgAdmin 4 (claimed vulnerable <= 9.9) by abusing the Restore feature for PLAIN-format dumps. - README.md: Vulnerability description, affected versions, mitigation guidance, and example reverse-shell command. - Exploit flow (CVE-2025-12762.py): 1) Creates a requests.Session() with TLS verification disabled (s.verify=False). 2) GETs /login and extracts a CSRF token from the HTML/JS via regex ("csrfToken": "..."). 3) POSTs credentials to /authenticate/login with csrf_token. 4) Uploads a crafted SQL file via /misc/file_manager/upload. The SQL includes a psql meta-command (\\! {COMMAND}) intended to execute an OS command on the pgAdmin host/container when processed. 5) Triggers execution by POSTing JSON to /restore/job/1 referencing the uploaded file, with format set to "plain" and database set to "postgres". - Capabilities: - Authenticated remote command execution on the pgAdmin server/container. - Payload is a single OS command string (default creates /tmp/CVE-2025-12762_PWNED). README suggests swapping COMMAND for a reverse shell one-liner. - Notable implementation details / limitations: - Hardcoded restore endpoint uses job id 1 (/restore/job/1), which may not exist on all instances. - Assumes the uploaded file is accessible to the restore process by name alone ("cve-2025-12762.sql"). - No robust verification of login success beyond printing messages; upload success check is a simple substring match. Overall purpose: provide an operational PoC demonstrating an authenticated RCE path in pgAdmin 4 via uploading a malicious PLAIN SQL dump and triggering a restore job that executes embedded shell commands.
This repository contains a working proof-of-concept exploit for CVE-2025-12762, a critical authenticated remote code execution (RCE) vulnerability in pgAdmin 4 versions 9.9 and below. The exploit is implemented in a single Python script (CVE-2025-12762.py) and is accompanied by a detailed README.md explaining the vulnerability, impact, and usage instructions. The exploit works by logging into the pgAdmin web interface using valid credentials, uploading a malicious SQL dump file in PLAIN format containing a shell command (using the \! syntax), and then triggering a restore operation. This causes the arbitrary command to be executed on the pgAdmin host system. The payload is customizable and can be set to any shell command, including spawning a reverse shell or creating a proof file. The attack is network-based and requires only low-privileged credentials. The script interacts with several pgAdmin HTTP endpoints, including login, authentication, file upload, and restore job endpoints. The exploit is operational and can be used for real-world exploitation in authorized environments. The README provides mitigation advice and emphasizes responsible use.
This repository contains a working proof-of-concept exploit for CVE-2025-12762, a critical authenticated remote code execution vulnerability in pgAdmin 4 versions 9.9 and below. The exploit is implemented in a single Python script (CVE-2025-12762.py) that automates the attack process: it logs into the pgAdmin web interface using provided credentials, uploads a specially crafted PLAIN-format SQL dump containing a shell command, and triggers the restore operation to execute the command on the server. The default payload creates a file on the target system, but it can be replaced with any shell command, including reverse shells. The attack is network-based and requires only low-privileged credentials. The README provides detailed context, usage instructions, and mitigation advice. The exploit targets the pgAdmin 4 web interface and interacts with several HTTP endpoints to perform authentication, file upload, and restore operations. The repository is well-structured, with clear separation between exploit code and documentation.
This repository contains a working proof-of-concept exploit for CVE-2025-12762, a critical authenticated remote code execution (RCE) vulnerability in pgAdmin 4 versions 9.9 and below. The exploit is implemented in a single Python script (CVE-2025-12762.py) that automates the attack: it logs into a target pgAdmin instance using provided credentials, uploads a malicious PLAIN-format SQL dump containing a system command, and triggers the restore operation, causing the command to execute on the pgAdmin host. The default payload creates a file on the target system as proof, but can be easily modified to execute arbitrary commands, including reverse shells. The README provides detailed context, usage instructions, and mitigation advice. The attack is network-based, requires authentication, and targets specific HTTP endpoints of the pgAdmin web interface. The exploit is a real, functional PoC and not a detection script or fake. No external framework is used; the code is standalone Python using the requests library.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.