Skip to main content

Proof-of-concept exploit code released for SQL injection vulnerability CVE-2025-1094

Summary

Proof-of-concept exploit code released for SQL injection vulnerability CVE-2025-1094

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

The PostgreSQL Global Development Group (also known as Postgres) has released an advisory to address a high severity vulnerability in PostgreSQL. PostgreSQL is a relational SQL database management system.

CVE-2025-1094 is an 'improper neutralisation of quoting syntax' vulnerability with a CVSSv3 score of 8.1. A remote unauthenticated attacker could execute arbitrary code with the privileges of the current site user by sending a specially crafted SQL statement. When exploited on a remote access agent, an attacker may achieve remote code execution.

Proof-of-concept code has been released for CVE-2025-1094.

Threat updates

Remediation advice

Affected organisations are encouraged to review PostgreSQL's CVE-2025-1094 security advisory and apply the relevant updates as soon as practicable.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 21 February 2025 1:08 pm