CVE-2025-2945 is a critical Remote Code Execution (RCE) vulnerability affecting pgAdmin 4 versions prior to 9.2, specifically within its Query Tool and Cloud Deployment modules. This flaw stems from the unsafe use of the Python eval() function with user-supplied parameters, allowing authenticated attackers to execute arbitrary code. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Exploit intelligence indicates the existence of a Metasploit module, suggesting readily available exploit code, and community discussions highlight its relevance in recent penetration testing scenarios, despite no confirmed active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2CPE matchmatch criteria | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.