SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x versions remain vulnerable.
"https://github.com/pypa/advisory-database/blob/main/vulns/sqlalchemy/PYSEC-2019-123.yaml"