Vulnerability intelligence
CVE-2026-17566
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job() (route POST /import_export/job/<sid>, gated only by the ordinary, commonly-granted tools_import_export_data permission) validated the query with a hand-written parenthesis-balance checker, _is_query_parens_balanced(). That checker always treated a backslash before a single quote (\') as escaping the quote, i.e. as if standard_conforming_strings were off.
CVSS Score
9.9
Critical
EPSS — Exploit Probability
0.6%
Riskier than 45% of all CVEs · checked 2026-09-19
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Aug 5, 2026 · latest Aug 5, 2026
Coverage timeline
-
Critical pgAdmin 4 Flaw Lets Attackers Run Code, Urges Patchsecurityonline.info · Aug 5, 2026