pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input.
{
"severity": "MODERATE",
"nvd_published_at": "2025-11-13T13:15:44Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-78"
],
"github_reviewed_at": "2025-11-13T23:09:41Z"
}