Forwarded from National Information Security Information Sharing and Analysis Center Security Alert NISAC-200-202601-00000012
Researchers have discovered a Code Injection vulnerability (CVE-2025-13780) in the PostgreSQL graphical interface tool pgAdmin. When the system is in Server Mode, a remote attacker with standard permissions can upload a specially crafted malicious backup file. Subsequently, when the restore function for PLAIN format backup files is triggered, the system will parse the malicious backup file, leading to arbitrary code execution on the pgAdmin host. Please verify and patch as soon as possible.