CVE-2025-2945

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 94

Summary

CVE-2025-2945 is a Remote Code Execution vulnerability affecting pgAdmin 4, specifically the Query Tool and Cloud Deployment modules. Two POST endpoints, /sqleditor/query_tool/download and /cloud/deploy, contain the issue. The query_committed parameter on the first endpoint and the high_availability parameter on the second are unsafely passed to the Python eval() function, enabling arbitrary code execution. This vulnerability affects pgAdmin 4 versions prior to 9.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share