SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
https://lists.debian.org/debian-lts-announce/2026/04/msg00025.html
https://github.com/geopandas/geopandas/pull/3681
https://aydinnyunus.github.io/2025/12/27/sql-injection-geopandas/