CVE-2025-9636

HIGH7.9EPSS 0.04%

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

Published: 9/5/2025Modified: 9/5/2025
Also known as:GHSA-6859-2qxq-ffv2

Description

pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.9CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L

References (4)