pgAdmin prior to 6.17 contains an insecure HTTP API caused by improper access control, letting unauthenticated users execute arbitrary external utilities via path manipulation, exploit requires no authentication.
id: CVE-2022-4223
info:
name: pgAdmin < 6.17 - Unauthenticated Remote Code Execution
author: 0x
...