SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-202",
"CWE-89"
],
"nvd_published_at": "2026-01-30T19:16:11Z",
"severity": "HIGH",
"github_reviewed_at": "2026-02-01T18:09:10Z"
}