VDB
Sign up
HIGH7.4

PYSEC-2026-1777

pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload

Quick fix

PYSEC-2026-1777 — pgadmin4: upgrade to the fixed version with the command below.

pip install --upgrade 'pgadmin4>=8.6'

Details

pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pgadmin4
Introduced in: 0Fixed in: 8.6
Fixpip install --upgrade 'pgadmin4>=8.6'

References