psql: Don't do backquote expansion in \unrestrict.

This oversight in commit 71ea0d6795 allows a malicious server to
inject shell commands into plain-text dump output that are run at
restore time on the machine running psql.  To fix, interpret all
text after \unrestrict until the end of the line as its argument.

Reported-by: Lucas Velgus <[email protected]>
Reported-by: Filip Janus <[email protected]>
Reported-by: Daniel Bakker <[email protected]>
Author: Nathan Bossart <[email protected]>
Reviewed-by: Robert Haas <[email protected]>
Reviewed-by: Noah Misch <[email protected]>
Security: CVE-2026-18408
Backpatch-through: 14

Branch
------
REL_17_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/0bfac9e1f946e098b1f61a642e71bb4844757472
Author: Nathan Bossart <[email protected]>

Modified Files
--------------
doc/src/sgml/ref/psql-ref.sgml |  5 +++++
src/bin/psql/command.c         | 10 ++++++++--
src/bin/psql/t/001_basic.pl    |  7 +++++++
3 files changed, 20 insertions(+), 2 deletions(-)

Reply via email to