CVE-2026-7817: Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to th...

Added to the CISA Known Exploited Vulnerabilities catalog on 11 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration endpoints. User-supplied api_key_file and api_url preferences were passed to the LLM provider clients without validation. An authenticated user could read arbitrary server-side fi...

Required action: Review and patch if applicable to your AI infrastructure.