CVE-2025-2945
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 94
Summary
CVE-2025-2945 is a Remote Code Execution vulnerability affecting pgAdmin 4, specifically the Query Tool and Cloud Deployment modules. Two POST endpoints, /sqleditor/query_tool/download and /cloud/deploy, contain the issue. The query_committed parameter on the first endpoint and the high_availability parameter on the second are unsafely passed to the Python eval() function, enabling arbitrary code execution. This vulnerability affects pgAdmin 4 versions prior to 9.2.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- pgAdmin
Affected Vendors
- Pgadmin