CVE-2025-12763 - Command injection vulnerability allowing arbitrary command execution on Windows

CVE-2025-12763 - Command injection vulnerability allowing arbitrary command execution on Windows

CVE ID : CVE-2025-12763 Published : Nov. 13, 2025, 1:15 p.m. | 14 minutes ago Description : pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path input. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Nov. 13, 2025
Affected Product: Windows
Impact: command injection