Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2026-7816

3 месяца назад

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could inject ") TO PROGRAM 'cmd'" to break out of the \copy (...) context and achieve arbitrary command execution on the pgAdmin server, or ") TO '/path'" for arbitrary file write. Additional fields (format, on_error, log_verbosity) were also raw-interpolated and exploitable. Fix adds a parens-balance parser modeled on psql's strtokx tokenizer, allow-lists format/on_error/log_verbosity, rejects null bytes in the query, and tightens type and gating checks. This issue affects pgAdmin 4: before 9.15.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-7816

3 месяца назад

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-j74f-g7vx-fh4x

3 месяца назад

pgAdmin 4: OS command injection vulnerability in Import/Export query export

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-09123

3 месяца назад

Уязвимость инструмента управления базами данных pgAdmin 4, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольную команду

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-7816

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated directly into a psql \copy metacommand template without sanitization. An authenticated user could inject ") TO PROGRAM 'cmd'" to break out of the \copy (...) context and achieve arbitrary command execution on the pgAdmin server, or ") TO '/path'" for arbitrary file write. Additional fields (format, on_error, log_verbosity) were also raw-interpolated and exploitable. Fix adds a parens-balance parser modeled on psql's strtokx tokenizer, allow-lists format/on_error/log_verbosity, rejects null bytes in the query, and tightens type and gating checks. This issue affects pgAdmin 4: before 9.15.

CVSS3: 8.8
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-7816

OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export ...

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-j74f-g7vx-fh4x

pgAdmin 4: OS command injection vulnerability in Import/Export query export

CVSS3: 8.8
1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-09123

Уязвимость инструмента управления базами данных pgAdmin 4, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольную команду

CVSS3: 8.8
1%
Низкий
3 месяца назад

Уязвимостей на страницу