The PGAdmin ERD Tool can open files on the server. The input is vulnerable to directory traversal. To abuse this, the POST can be altered: Steps to reproduce: 1. Open Tools -> ERD Tool 2. Choose Open File 3. Change POST (/pgadmin4/sqleditor/load_file/ ) <img width="992" alt="Screenshot 2022-11-14 at 11 44 41" src="https://user-images.githubusercontent.com/15089870/201641553-2d494a80-e40d-4d0a-9c12-c96ca8b47394.png">