{"id":"CVE-2025-13780","title":"pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files","summary":"pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbit…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","cwe":["CWE-94"],"vendor":"pgadmin","product":"pgadmin_4","affected":["pgadmin_4 <= 9.10"],"published":"2025-12-11","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13780","references":[{"url":"https://github.com/pgadmin-org/pgadmin4/issues/9368","label":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"tags":["nvd","exploit-available"],"epss":0.00943,"epssPercentile":0.59748,"exploits":{"github":3,"githubRepos":["https://github.com/zeropwn/pgadmin4-9.10-CVE-2025-13780","https://github.com/ThemeHackers/CVE-2025-13780","https://github.com/meenakshisl/PoC-CVE-2025-13780"],"checkedAt":"2026-10-07T20:47:22.823Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T20:46:46.857Z","slug":"CVE-2025-13780","body":"## Overview\n\npgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting pgAdmin, posing a critical risk to the integrity and security of the database management system and underlying data.\n\n## Affected\n\n- `pgadmin_4 <= 9.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}