THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-17351 (CRITICAL 9.0) — The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's str

[NVD] CVE-2026-17351 (CRITICAL 9.0) — The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's str

mednvdPublished 2026-07-31

CVE-2026-17351 CVSS: 9.0 CRITICAL Published: 2026-07-31T16:16:59.807

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17351