psql: Don't do backquote expansion in \unrestrict. This oversight in commit 71ea0d6795 allows a malicious server to inject shell commands into plain-text dump output that are run at restore time on the machine running psql. To fix, interpret all text after \unrestrict until the end of the line as its argument.
Reported-by: Lucas Velgus <[email protected]> Reported-by: Filip Janus <[email protected]> Reported-by: Daniel Bakker <[email protected]> Author: Nathan Bossart <[email protected]> Reviewed-by: Robert Haas <[email protected]> Reviewed-by: Noah Misch <[email protected]> Security: CVE-2026-18408 Backpatch-through: 14 Branch ------ REL_15_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/df245c37458315cf8a6ff08f4f8c3b1103857ed3 Author: Nathan Bossart <[email protected]> Modified Files -------------- doc/src/sgml/ref/psql-ref.sgml | 5 +++++ src/bin/psql/command.c | 19 +++++++++++++++++-- src/bin/psql/t/001_basic.pl | 7 +++++++ 3 files changed, 29 insertions(+), 2 deletions(-)
