VDB
Sign up
HIGH8.6

PYSEC-2026-1775

OAuth2 client ID and secret exposed through the web browser

Quick fix

PYSEC-2026-1775 — pgadmin4: upgrade to the fixed version with the command below.

pip install --upgrade 'pgadmin4>=8.12'

Details

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pgadmin4
Introduced in: 0Fixed in: 8.12
Fixpip install --upgrade 'pgadmin4>=8.12'

References