CVE-2025-2945·Python vulnerability
Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoints; /sqleditor/query_tool/download, where the query_commited parameter and /cloud/deploy endpoint, where the high_availability parameter is unsafely passed to the Python eval() function, allowing arbitrary code execution. This issue affects pgAdmin 4: before 9.2.
- Severity
- critical
- Software
- Python
- Fixed in
- 9.2
- Published
- 2025-04-03
Affected versions
Until: 9.2
Fixed in: 9.2
How to fix this CVE
Upgrade pgAdmin 4 to version 9.2 or later, which removes unsafe eval() calls from the query tool and cloud deployment modules. This vulnerability allows authenticated attackers to execute arbitrary Python code through two specific POST endpoints. Immediately patch all pgAdmin 4 instances running versions prior to 9.2 in your environment.
sudo dnf update pgadmin4 && sudo systemctl restart pgadmin4Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /sqleditor/query_tool/download HTTP/1.1.*query_committed=.*(__import__|eval|exec|compile|os\.|sys\.|subprocess) or POST /cloud/deploy HTTP/1.1.*high_availability=.*(__import__|eval|exec|compile|os\.|sys\.|subprocess)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or require authentication for POST requests to /sqleditor/query_tool/download and /cloud/deploy. Implement input validation to reject any query_committed or high_availability parameters containing Python built-in function names (eval, exec, compile, __import__, etc.) or module imports (os, sys, subprocess, socket). Use ModSecurity rules to detect eval() payloads.How to check if you are affected
- Check pgAdmin 4 version: grep -r 'version' /pgadmin4/config_distro.py | grep -i version or access the pgAdmin web UI and check Settings > About
- Verify exposed endpoints: curl -s http://localhost:5050/sqleditor/query_tool/download -X OPTIONS -v | grep Allow and curl -s http://localhost:5050/cloud/deploy -X OPTIONS -v | grep Allow
- Search web server logs for POST requests to /sqleditor/query_tool/download or /cloud/deploy with suspicious query_committed or high_availability parameters: grep -E '(query_tool/download|cloud/deploy)' /var/log/pgadmin4/pgadmin4.log | grep POST
- Confirm remediation by running: pgadmin4 --version and verify output shows 9.2 or later
FAQ
What is CVE-2025-2945?
CVE-2025-2945 is a critical remote code execution vulnerability in pgAdmin 4 that stems from unsafe use of Python's eval() function in the Query Tool and Cloud Deployment modules. Authenticated users can inject arbitrary Python code through POST parameters to achieve code execution on the pgAdmin server.
Is CVE-2025-2945 being actively exploited?
No, according to CISA's Known Exploited Vulnerabilities (KEV) catalog, there is currently no evidence of active exploitation in the wild. However, the critical CVSS 9.9 score and public issue disclosure warrant immediate patching.
What versions of pgAdmin 4 are affected by CVE-2025-2945?
All versions of pgAdmin 4 prior to version 9.2 are vulnerable. The vulnerability was patched in pgAdmin 4 version 9.2 and later.
How do I check if my server is vulnerable to CVE-2025-2945?
Run 'pgadmin4 --version' to retrieve your installed version. If the output is 9.1 or earlier, your installation is vulnerable. Additionally, check if the endpoints /sqleditor/query_tool/download and /cloud/deploy are accessible to authenticated users.
Does Defensia detect CVE-2025-2945?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If pgAdmin 4 is installed on a monitored server, CVE-2025-2945 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-2945. Free for 1 server.
Get started free