THREAT OPS › Threat News › [NVD] CVE-2026-17351 (CRITICAL 9.0) — The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's str
[NVD] CVE-2026-17351 (CRITICAL 9.0) — The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's str
CVE-2026-17351 CVSS: 9.0 CRITICAL Published: 2026-07-31T16:16:59.807
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's string-literal lexing can disagree with PostgreSQL's
Indicators of compromise
- CVE-2026-17351cve
- CVE-2026-12045cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17351