Inclusion of Functionality from Untrusted Control Sphere Affecting libpq package, versions [,14.9)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-LIBPQ-12008957
  • published19 Aug 2025
  • disclosed14 Aug 2025
  • creditMartin Rakhmanov, Matthieu Denais, RyotaK

Introduced: 14 Aug 2025

NewCVE-2025-8714  (opens in a new tab)
CWE-829  (opens in a new tab)

How to fix?

Upgrade libpq to version 14.9 or higher.

Overview

Affected versions of this package are vulnerable to Inclusion of Functionality from Untrusted Control Sphere when restoring from a plain-text dump file. An attacker can embed malicious psql meta-commands into dump files generated by pg_dump --format=plain, pg_dumpall, or pg_restore --file. Once the dump is restored using psql, these commands will execute, allowing arbitrary code to run on the system performing the restore.

CVSS Base Scores

version 4.0
version 3.1