CVE-2025-9636: pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker to manipulate the OAuth flow, potentially leading to unauthorised account access, account takeover, data breaches, and privilege escalation.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-9636 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →