SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
https://github.com/geopandas/geopandas/pull/3681
https://aydinnyunus.github.io/2025/12/27/sql-injection-geopandas/