
[CVE-2026-29089: HIGH] Critical security vulnerability in TimescaleDB versions 2.23.0 to 2.25.1 patched in 2.25.2. PostgreSQL search_path flaw could lead to arbitrary code execution during upgrade.#cve,CVE-2026-29089,#cybersecurity https://cvefind.com/CVE-2026-29089
Post summary
TimescaleDB versions 2.23.0 to 2.25.1 are vulnerable to an arbitrary code execution flaw during upgrade caused by a PostgreSQL search_path issue; the issue is fixed in 2.25.2.


