This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59470.json"
[ { "events": [ { "introduced": "13.0.0.4967" }, { "fixed": "13.0.1.1071" } ] } ]