CVE-2025-2946
CRITICALpgAdmin <= 9.1 - Cross-Site Scripting via Query Result Rendering
Title source: llmDescription
pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.
References (1)
Core 1
Core References
Issue Tracking issue-tracking
https://github.com/pgadmin-org/pgadmin4/issues/8602
Scores
CVSS v3
9.1
EPSS
0.0011
EPSS Percentile
29.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
pgadmin/pgadmin_4
< 9.1
pypi/pgadmin4
0 - 9.2PyPI
Published
Apr 03, 2025
Tracked Since
Feb 18, 2026