pgAdmin prior to 6.17 contains an insecure HTTP API caused by improper access control, letting unauthenticated users execute arbitrary external utilities via path manipulation, exploit requires no authentication.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view