Impact
pgAdmin 4's File Manager save_file endpoint allows an attacker to write an arbitrary file outside the allotted user storage directory by leveraging a race condition between a permissions check and an unprotected open() call. The vulnerability permits filesystem writes to any location reachable by the operating‑system account running pgAdmin, effectively giving local attackers the ability to overwrite or create arbitrary files. This weakness is consistent with CWE-367 (Race Condition) and CWE-59 (Symbolic Link Dereference).
Affected Systems
This defect affects all pgAdmin 4 installations up to and including version 9.17, as the containment check introduced before 9.18 did not guard the final path component with O_NOFOLLOW. The vulnerability is publicly documented for the pgadmin.org:pgAdmin 4 product line, but no specific patch version is listed in the provided data. Administrators should verify whether their installation is at or below 9.17.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting limited evidence of exploitation. Successful exploitation requires filesystem write access or the ability to create or replace a symbolic link within the user’s storage directory, and precise timing to replace the link between the check and the write. Because the attack only succeeds when the attacker controls the filesystem or shares a network‑mounted backend, the likelihood of exploitation is low in tightly controlled environments but remains a concern in scenarios where users have local filesystem privileges.
OpenCVE Enrichment