CVE-2025-8714
PostgreSQL: pg_dump lets a superuser of the origin server inject code that runs at restore
Technology
PostgreSQL
CVSS Score
8.8 / 10.0
Affected Versions
Before 17.6, 16.10, 15.14, 14.19 and 13.22 (12 and older not assessed)
Upstream Fix
17.6; 16.10; 15.14; 14.19; 13.22
Published
August 14, 2025
OSSeva Coverage
Fixed upstream
Description
pg_dump included untrusted data in its output, so a malicious superuser of the origin server could inject psql meta-commands that run arbitrary code as the client operating system account restoring the dump with psql. pg_dumpall is also affected, and pg_restore when it generates a plain-format dump. Scored 8.8 by PostgreSQL as the CNA. Fixed in 17.6, 16.10, 15.14, 14.19 and 13.22.
Is your PostgreSQL deployment affected?
If you're running Before 17.6, 16.10, 15.14, 14.19 and 13.22 (12 and older not assessed), you need this patch. Book a discovery call to get covered.