pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
{
"github_reviewed": true,
"github_reviewed_at": "2025-11-13T23:09:41Z",
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"nvd_published_at": "2025-11-13T13:15:44Z"
}