Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-17351— pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)

CVSS 9.0 · Critical EPSS 0.38% · P31

Affected Version Matrix 1

VendorProductVersion RangeStatus
pgadmin.orgpgAdmin 49.13< 9.17affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-17351

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
Source: CVE Program / CVE List V5
Vulnerability Description
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's own parser: under standard_conforming_strings = on (PostgreSQL's default since 9.1), a backslash immediately before a quote is an ordinary character to PostgreSQL, but sqlparse treats it as escaping the quote. A payload such as SELECT '\';COMMIT;CREATE TABLE pwn(x int);SELECT 1 --' therefore parses as a single SELECT to sqlparse's validator, while PostgreSQL executes it as four statements: the smuggled COMMIT ends the wrapping read-only transaction, and the trailing ROLLBACK becomes a no-op. This reintroduces the same write/RCE bypass CVE-2026-12045 was meant to close, reachable via the same indirect prompt-injection delivery (an attacker plants the payload in any object the AI Assistant may read; the LLM emits it as a tool call). An initial candidate fix ran the query with psycopg's execute(..., prepare=True), intending to force PostgreSQL's own Parse step (extended query protocol) to reject multi-statement text regardless of sqlparse's classification. This candidate fix does not work as submitted: psycopg3's PrepareManager silently ignores the prepare argument whenever the connection's prepare_threshold is None, which is pgAdmin's default for every server connection (the per-server "Prepare threshold" field is blank unless an administrator explicitly sets it) -- psycopg3 falls back to the simple query protocol, the same multi-statement-capable path the bypass exploits, so the candidate fix closes nothing on any real-world default configuration. The corrected fix sets conn.prepare_threshold = 0 directly on the dedicated, single-use read-only connection the AI Assistant tool opens, structurally forcing the extended query protocol independent of any server-level configuration. Verified against a live PostgreSQL 18 instance: the payload executes successfully under the prepare_threshold=None (default) behavior, and is rejected with "cannot insert multiple commands into a prepared statement" once prepare_threshold=0 is set on that connection. This issue affects pgAdmin 4: from 9.13 before 9.17.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5
Vulnerability Title
pgAdmin 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
pgAdmin是pgAdmin组织开源的一个用于开源数据库 PostgreSQL 的开源管理和开发平台。 pgAdmin 9.13版本至9.17之前版本存在安全漏洞,该漏洞源于AI Assistant的execute_sql_query工具对LLM提供的查询参数验证不当,sqlparse与PostgreSQL解析器对字符串字面量处理不一致,可能允许攻击者通过间接提示注入绕过只读事务限制,导致写入或远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
pgadmin.orgpgAdmin 4 9.13 ~ 9.17 -

II. Public POCs for CVE-2026-17351

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 10560 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-17351

登录查看更多情报信息。

Patches & Fixes for CVE-2026-17351 (1)

Other References for CVE-2026-17351 (1)

Same Patch Batch · pgadmin.org · 2026-07-31 · 7 CVEs total

CVE-2026-175669.9 CRITICALpgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete
CVE-2026-173499.6 CRITICALpgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownersh
CVE-2026-173468.8 HIGHpgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/su
CVE-2026-173477.5 HIGHpgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutio
CVE-2026-173486.5 MEDIUMpgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Sche
CVE-2026-173505.4 MEDIUMpgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers

IV. Related Vulnerabilities

V. Comments for CVE-2026-17351

No comments yet


Leave a comment