Impact
pgAdmin 4’s Backup tool improperly appended the client‑supplied database field directly to the pg_dump argument list, allowing values that begin with a dash to be interpreted as operational options. A value such as --file=/absolute/path overrode the tool’s intended location, permitting an attacker to write files anywhere the pgAdmin process could access. Additionally, the field was vulnerable to connection‑string injection; libpq interpreted a database name containing an equals sign as a full connection string, enabling redirection of pg_dump to an attacker‑controlled server. Because pgAdmin exported the decrypted database password into the environment variable PGPASSWORD before executing pg_dump, the sensitive credential was sent to the attacker’s endpoint. These behaviors expose serious confidentiality, integrity, and availability risks, including arbitrary file overwrite and potential escalation of privileges when the overwritten resources belong to pgAdmin’s configuration.
Affected Systems
The vulnerability exists in pgAdmin 4 from the introduction of the trailing positional database argument in the Backup tool before version 9.18. Affected vendors and products identified by the CNA are pgadmin.org’s pgAdmin 4. All earlier releases before 9.18 are susceptible.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, with no EPSS score available and it is not listed in the CISA KEV catalog. The attack requires a legitimate user account that has the tools_backup permission, which is granted by default to the User role. An attacker can therefore exploit the flaw by submitting a crafted request to the /backup/job/<sid>/object API. The inferred attack vector is a remote web‑interface interaction with authenticated access, and any user with the necessary permission can deliver the exploit. Taken together, the high CVSS score and availability of a direct exploit path underscore that the vulnerability poses a significant risk to affected installations.
OpenCVE Enrichment