CVE-2025-52467

Source
https://cve.org/CVERecord?id=CVE-2025-52467
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52467.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-52467
Aliases
  • GHSA-89qq-hgvp-x37m
Published
2025-06-19T02:50:51.240Z
Modified
2026-04-02T12:52:13.414135Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
pgai secrets exfiltration via `pull_request_target`
Details

pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repository was vulnerable to an attack allowing the exfiltration of all secrets used in one workflow. In particular, the GITHUB_TOKEN with write permissions for the repository, allowing an attacker to tamper with all aspects of the repository, including pushing arbitrary code and releases. This issue has been patched in commit 8eb3567.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52467.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/timescale/pgai

Affected ranges

Type
GIT
Repo
https://github.com/timescale/pgai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

extension-0.*
extension-0.10.0
extension-0.10.1
extension-0.4.0
extension-0.4.1
extension-0.5.0
extension-0.6.0
extension-0.7.0
extension-0.8.0
extension-0.9.0
pgai-v0.*
pgai-v0.10.0
pgai-v0.10.1
pgai-v0.10.2
pgai-v0.10.3
pgai-v0.2.0
pgai-v0.2.1
pgai-v0.3.0
pgai-v0.4.0
pgai-v0.5.0
pgai-v0.6.0
pgai-v0.7.0
pgai-v0.8.0
pgai-v0.8.1
pgai-v0.8.2
pgai-v0.8.3
pgai-v0.8.4
pgai-v0.9.0
pgai-v0.9.1
pgai-v0.9.2
v0.*
v0.1.0
v0.2.0
v0.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52467.json"