#PgAdmin
I am coming around to why MCP is so impressive.

For one of my side projects, I used to have to log onto my database admin (PgAdmin) to query stuff.

I connected an MCP server to Postgres and can "talk" with my database (and data!)

An uplevel in my productivity + ease of work.
April 5, 2025 at 8:35 PM
#exploit #vulnerability #RCE #zeroday #flaw #POC for Remote Code Execution Vulnerability in pgAdmin 4 CVE-2025-2945 github.com/pgadmin-org/...
Fixed a remote code execution issue in the Query Tool and Cloud Deplo… · pgadmin-org/pgadmin4@75be0bc
…yment (CVE-2025-2945). #8603
github.com
November 18, 2025 at 5:51 PM
I came across this great tutorial by Oskar Dudycz for setting up a PostgreSQL database and PGadmin IDE inside a container:
event-driven.io/en/automatic...

#docker #postgres #data
How to automatically setup pgAdmin with a Docker database - Event-Driven.io
Event-Driven by Oskar Dudycz
event-driven.io
June 24, 2025 at 12:43 PM
Bora atualizar o pgAdmin? #bolhasec

O fix do CVE-2024-9014 tá na versão 8.12

(não sigam o meu exemplo 🤣)
September 25, 2024 at 10:16 PM
*Schweizer CTO Voice*

Um mehr Frauen für unser Unternehmen zu gewinnen, verwenden wir als Datenbank Postgres, weil die pgAdmin-Oberfläche so schön bunt ist.
Die Schweiz ist echt nochmal anders wild.
May 27, 2024 at 8:22 PM
I asked ChatpGPT to migrate the #SQLServer Create script for the Contoso generated dataset to #Postgres and it just worked? This is exciting.
November 18, 2024 at 2:17 PM
April 7, 2026 at 4:00 PM
Bom dia, amigos

Segundou? #bolhasec

Vulnerabilidade crítica (CVSS 9.9) no pgAdmin 4 🔥🔥

nvd.nist.gov/vuln/detail/...
NVD - CVE-2025-2945
nvd.nist.gov
April 7, 2025 at 10:55 AM
And the Route53 one was busy porting over pgAdmin.
December 6, 2024 at 7:30 AM
Наскільки ж чудовий PostgreSQL, настільки ж жахливий pgAdmin
April 3, 2026 at 3:56 AM
📌 CVE-2026-86863 - pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, deliver... https://www.cyberhub.blog/cves/CVE-2026-86863
CVE-2026-86863
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned
www.cyberhub.blog
September 22, 2026 at 8:37 AM
Critical pgAdmin Vulnerability Let Attackers Execute Shell Commands on the Host
Critical pgAdmin Vulnerability Let Attackers Execute Shell Commands on the Host
cybersecuritynews.com
December 15, 2025 at 5:16 PM
Pra completar a tarde #bolhasec

Apocalipse no mundinho backend

CVE-2024-9014 crítico (CVSS 9.9) no pgAdmin 8.11 e inferiores

Boa tarde?
September 25, 2024 at 10:07 PM
That's really everything there is to it?

Amazing stuff. Honestly great job @maddymontaquila.net @davidfowl.com and everyone else that was involved with this!
January 24, 2025 at 10:53 AM
abrir o pgadmin me da calafrios me voltam memórias de guerra
October 2, 2024 at 5:17 PM
CVE-2026-86863 - pgadmin 4
When pgAdmin 4 is set to rely on the web server to confirm a user's identity, an attacker can send a custom request header and be accepted as any user, even an administrator,…

Too many irrelevant or confusing CVEs? Use stackflag.com

#pgadmin4 #pgadminorg #CVE #infosec
CVE-2026-86863: pgAdmin 4 allows password‑less login with forged header
When pgAdmin 4 is set to rely on the web server to confirm a user's identity, an attacker can send a custom request header and be accepted as any user,.
stackflag.com
September 17, 2026 at 5:40 PM
Esse foi o fix

Bora atualizar?

github.com/pgadmin-org/...
September 25, 2024 at 10:13 PM
🚨CVE-2025-2945: pgAdmin 4 Vulnerable to Remote Code Execution

FOFA Link: en.fofa.info/result?qbase...

FOFA Query: body="pg-sp-content" && title="pgAdmin 4"

Results: 44,485

Advisory: github.com/advisories/G...

CVSS: 10
June 3, 2025 at 7:12 PM
During a recent Red Team Assessment @thezero.org and @smaury.bsky.social discovered a vulnerability in PostgreSQL's #PgAdmin which in the worst case allows unauthenticated attackers to run arbitrary server-side code.

Check out the #RCE advisory and patch now!
www.shielder.com/advisories/p...
Shielder - pgAdmin (<=8.3) Path Traversal in Session Handling Leads to Unsafe Deserialization and Remote Code Execution (RCE)
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing user's session in the session handling code. If the server is running on Windows, an unauthenticated attacker can load ...
www.shielder.com
March 8, 2024 at 1:55 PM
June 19, 2026 at 1:00 AM
bsky.app/profile/lean...

sei que ja resolveu, mas eu sempre recorro à tabela pg_stat_activity pra pegar essas informacoes.

inclusive o dashboard do pgadmin é basicamente uma query nessa tabela
diria que nem precisa de habilitar o pg_stat_statements pra saber de onde vem o diabo da requisicao.

a tabela pg_stat_activity é padrão no postgres e traz informacoes de onde vem as queries atraves do campo application_name
September 28, 2024 at 12:08 AM
Хотів зручно підключити postgres базу мастодон до pgAdmin але ніяк не пінгується ніде. Буду бекапити через консольку
March 21, 2025 at 10:59 AM
📌 CVE-2026-86864 - pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job//object request to the pg_dump argument vector as a ba... https://www.cyberhub.blog/cves/CVE-2026-86864
CVE-2026-86864
pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning
www.cyberhub.blog
September 24, 2026 at 11:37 AM
PgAdmin is my best friend
September 12, 2023 at 8:57 PM