pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
CVE ID: CVE-2024-3116
CVSS Base Severity: HIGH
CVSS Base Score: 7.4
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Vendor: pgadmin.org
Product: pgAdmin 4
EPSS Score: 14.31% (probability of being exploited)
EPSS Percentile: 95.82% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)