PT-2026-39627 · Pgadmin 4+1 · Pgadmin 4+1

J3Seer

·

Published

2026-05-11

·

Updated

2026-05-26

·

CVE-2026-7817

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pgAdmin 4 versions prior to 9.15
Description Local file inclusion (LFI) and server-side request forgery (SSRF) issues exist in the LLM API configuration endpoints. Authenticated users can read arbitrary server-side files by providing a path to the api key file preference, or force the application to make requests to internal targets, such as cloud metadata services, by manipulating the api url preference. These issues are exploitable via the chat path and model-list endpoints.
Recommendations Update to version 9.15 or later. Restrict the api url using the config.ALLOWED LLM API URLS allow-list at every entry point.

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7817
GHSA-P58C-Q354-6C4F

Affected Products

Pgadmin
Pgadmin 4