CVE-2025-2945 | pgAdmin 4 up to 9.1 Cloud Deployment download eval query_commited code injection (Nessus ID 234350 / WID-SEC-2025-0708)
A vulnerability labeled as very critical has been found in pgAdmin 4 up to 9.1. This vulnerability affects the function eval of the file /sqleditor/query_tool/download of the component Cloud Deployment Module. Such manipulation of the argument query_commited leads to code injection.
This vulnerability is uniquely identified as CVE-2025-2945. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.