GHSA-rj98-crf4-g69w · Severity: critical · Ecosystem: pip — pgAdmin 4 vulnerable to Unsafe Deserialization and Remote Code Execution by an Authenticated user
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.
Conclusion & alert: CVE-2024-2044 is rated High Exploit Risk (85.3/100): CVSS Critical severity, with high exploitation likelihood (EPSS 79.33%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 83.47% | 79.33% | -4.15% |
| 2 | 2026-03-26 | 80.90% | 83.47% | +2.57% |
| 3 | 2025-11-21 | — | 80.90% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 |
GHSA-rj98-crf4-g69w · Severity: critical · Ecosystem: pip — pgAdmin 4 vulnerable to Unsafe Deserialization and Remote Code Execution by an Authenticated user
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
high | CVE-2024-2044 severity important: SUSE including 21 source package names (pgadmin4, pgadmin4-4.1-150100.3.9.2, …), 71 product×package rows across 21 product lines (SUSE Enterprise Storage 7.1, SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS, … (21 product lines)): Fixed 61, Known Not Affected 10. | https://www.suse.com/security/cve/CVE-2024-2044/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pgadmin | pgadmin_4 | < 8.4 | cpe:2.3:a:pgadmin:pgadmin_4:*:*:*:*:*:postgresql:*:* |
| fedoraproject | fedora | 40 | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/pgadmin-org/pgadmin4/issues/7258 | Issue Tracking Vendor Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/LUYN2JXKKHFSVTASH344TBRGWDH64XQV/ | Mailing List |
| https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/ | Exploit Third Party Advisory |