Skip to content

Vulnerability Inquiry – Node.js Dependency in PostGres 18.4 pgAdmin 4 v9.15 (CVE-2025-27210) #10166

Description

@udayrachati

Dear pgAdmin Team,

We performed a Black Duck Binary Analysis security scan on PostgreSQL 18.4-1 and pgAdmin 4 version 9.15. During the scan, we identified a potential security vulnerability associated with the bundled Node.js runtime included with pgAdmin.

Vulnerability Details

CVE: CVE-2025-27210

Description
Node.js is reported to be vulnerable to a path traversal issue due to improper handling of Windows reserved device names (such as CON, PRN, AUX, and NUL) when using the path.join() API. Under certain conditions, this vulnerability could allow unauthorized access to files in Node.js applications running on Windows.

Our Findings

Product: pgAdmin 4
Version: 9.15
Bundled Node.js Version: 22.15.x
Scan Tool: Black Duck Binary Analysis

The scan reports that this issue is related to CVE-2025-27210 and indicates that it is an incomplete fix for the original vulnerability.

Could you please help clarify the following:

Is pgAdmin 4 version 9.15 affected by CVE-2025-27210?
Has this vulnerability already been addressed in a newer pgAdmin release or by updating the bundled Node.js runtime?
If a fix is available, could you please let us know which pgAdmin version includes it?
If a fix is not yet available, is there a planned timeline for addressing this vulnerability?
Are there any recommended mitigations or workarounds for customers using pgAdmin 4 version 9.15 on Windows?

If required, we can also provide the Black Duck scan report for your reference.

We appreciate your assistance and look forward to your guidance.

Regards,
Uday Kumar R

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions