In pgAdmin versions up to and including 9.9 a critical vulnerability CVE-2025-12762 was identified. When running in server mode, pgAdmin is vulnerable to remote code execution (RCE) during restore operations from PLAIN-format SQL dump files. An attacker could exploit this flaw to inject and execute arbitrary commands on the system hosting pgAdmin, compromising both the database management environment and underlying server data. Users are strongly advised to upgrade to pgAdmin version 10.0 or later to mitigate this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-12762.
pgAdmin: Remote Code Execution Vulnerability in Server Mode During PLAIN-Format Restore
by the Hossted team
13.11.2025