PT-2025-26203 · Pypi · Pgai
Albertopellitteri
+2
·
Published
2025-06-18
·
Updated
2025-06-19
·
CVE-2025-52467
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
pgai versions prior to 8eb3567
Description
The issue concerns the pgai Python library, which transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to a specific commit, the library was vulnerable to an attack that allowed the exfiltration of all secrets used in one workflow. This included the GITHUB TOKEN with write permissions for the repository, enabling an attacker to tamper with all aspects of the repository, such as pushing arbitrary code and releases.
Recommendations
For versions prior to 8eb3567, update to a version that includes the fix from commit 8eb3567 to prevent the exfiltration of secrets. As a temporary workaround, consider restricting access to sensitive information and secrets within the workflow to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pgai