psql: Don't do backquote expansion in \unrestrict.
This oversight in commit 71ea0d6795 allows a malicious server to
inject shell commands into plain-text dump output that are run at
restore time on the machine running psql. To fix, interpret all
text after \unrestrict until the end of the line as its argument.
Reported-by: Lucas Velgus <velgusgus599@gmail.com>
Reported-by: Filip Janus <fjanus@redhat.com>
Reported-by: Daniel Bakker <daniel@jackds.nl>
Author: Nathan Bossart <nathandbossart@gmail.com>
Reviewed-by: Robert Haas <robertmhaas@gmail.com>
Reviewed-by: Noah Misch <noah@leadboat.com>
Security: CVE-2026-18408
Backpatch-through: 14
Branch
------
master
Details
-------
https://git.postgresql.org/pg/commitdiff/086f6f1760140a0055c2faa8d6831fd3ebaf96b0
Author: Nathan Bossart <nathan@postgresql.org>
Modified Files
--------------
doc/src/sgml/ref/psql-ref.sgml | 5 +++++
src/bin/psql/command.c | 10 ++++++++--
src/bin/psql/t/001_basic.pl | 7 +++++++
3 files changed, 20 insertions(+), 2 deletions(-)