Dear pgAdmin Team,
We performed a Black Duck Binary Analysis security scan on PostgreSQL 18.4-1 and pgAdmin 4 version 9.15. During the scan, we identified a potential security vulnerability associated with the bundled Node.js runtime included with pgAdmin.
Vulnerability Details
CVE: CVE-2025-27210
Description
Node.js is reported to be vulnerable to a path traversal issue due to improper handling of Windows reserved device names (such as CON, PRN, AUX, and NUL) when using the path.join() API. Under certain conditions, this vulnerability could allow unauthorized access to files in Node.js applications running on Windows.
Our Findings
Product: pgAdmin 4
Version: 9.15
Bundled Node.js Version: 22.15.x
Scan Tool: Black Duck Binary Analysis
The scan reports that this issue is related to CVE-2025-27210 and indicates that it is an incomplete fix for the original vulnerability.
Could you please help clarify the following:
Is pgAdmin 4 version 9.15 affected by CVE-2025-27210?
Has this vulnerability already been addressed in a newer pgAdmin release or by updating the bundled Node.js runtime?
If a fix is available, could you please let us know which pgAdmin version includes it?
If a fix is not yet available, is there a planned timeline for addressing this vulnerability?
Are there any recommended mitigations or workarounds for customers using pgAdmin 4 version 9.15 on Windows?
If required, we can also provide the Black Duck scan report for your reference.
We appreciate your assistance and look forward to your guidance.
Regards,
Uday Kumar R
Dear pgAdmin Team,
We performed a Black Duck Binary Analysis security scan on PostgreSQL 18.4-1 and pgAdmin 4 version 9.15. During the scan, we identified a potential security vulnerability associated with the bundled Node.js runtime included with pgAdmin.
Vulnerability Details
CVE: CVE-2025-27210
Description
Node.js is reported to be vulnerable to a path traversal issue due to improper handling of Windows reserved device names (such as CON, PRN, AUX, and NUL) when using the path.join() API. Under certain conditions, this vulnerability could allow unauthorized access to files in Node.js applications running on Windows.
Our Findings
Product: pgAdmin 4
Version: 9.15
Bundled Node.js Version: 22.15.x
Scan Tool: Black Duck Binary Analysis
The scan reports that this issue is related to CVE-2025-27210 and indicates that it is an incomplete fix for the original vulnerability.
Could you please help clarify the following:
Is pgAdmin 4 version 9.15 affected by CVE-2025-27210?
Has this vulnerability already been addressed in a newer pgAdmin release or by updating the bundled Node.js runtime?
If a fix is available, could you please let us know which pgAdmin version includes it?
If a fix is not yet available, is there a planned timeline for addressing this vulnerability?
Are there any recommended mitigations or workarounds for customers using pgAdmin 4 version 9.15 on Windows?
If required, we can also provide the Black Duck scan report for your reference.
We appreciate your assistance and look forward to your guidance.
Regards,
Uday Kumar R