pgAdmin 4 v9.17 Released: 7 CVEs Fixed, New Row Cap, and Electron 43 Upgrade

Published by

pgAdmin 4 v9.17 was released on July 30, 2026, and addresses seven security vulnerabilities, including critical flaws related to command injection and credential cloning. The update introduces a new row count cap for the "View Data" action, designed to prevent accidental full-table scans on large databases, along with other enhancements such as support for custom XYZ tile providers and improved audit trails in server-mode deployments. Additionally, the application has upgraded to Electron 43.1.1 and improved supply chain hardening in its macOS build process. Users, especially those in server mode with shared servers or external authentication, are advised to apply the patch immediately and review their configurations to ensure security



pgAdmin 4 v9.17 Released: 7 CVEs Fixed, New Row Cap, and Electron 43 Upgrade

pgAdmin 4 v9.17 dropped on July 30, 2026, addressing seven security vulnerabilities including critical command injection and credential cloning flaws, with three stemming from incomplete patches in the previous release. The update introduces four practical enhancements, led by a new row count cap for the View Data action that helps prevent accidental full-table scans on large databases. Under the hood, the application upgrades to Electron 43.1.1, pins Yarn to 4.15.0, and implements stricter supply chain hardening across the macOS build process and GitHub Actions. Operators running server mode, especially those using shared servers or external authentication, should apply the patch immediately.

pgAdmin 4 v9.17 Released: 7 CVEs Fixed, New Row Cap, and Electron 43 Upgrade @ Linux Compatible