SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
"https://github.com/pypa/advisory-database/blob/main/vulns/geopandas/PYSEC-2026-62.yaml"