SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
"https://github.com/pypa/advisory-database/blob/main/vulns/sqlalchemy/PYSEC-2019-123.yaml"