phpPgAdmin 7.13.0 contains a remote command execution vulnerability that allows authenticated attackers to execute arbitrary system commands through SQL query manipulation. Attackers can create a custom table, upload a malicious .txt file, and use the COPY FROM PROGRAM command to execute operating system commands with the application's privileges.
{
"nvd_published_at": "2026-01-21T18:16:14Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-78"
],
"github_reviewed_at": "2026-02-02T20:33:47Z",
"github_reviewed": true
}