SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
References
| Link | Resource |
|---|---|
| https://aydinnyunus.github.io/2025/12/27/sql-injection-geopandas/ | Exploit Third Party Advisory |
| https://github.com/geopandas/geopandas/pull/3681 | Issue Tracking Patch |
Configurations
History
11 Feb 2026, 18:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:geopandas:geopandas:*:*:*:*:*:python:*:* | |
| First Time |
Geopandas
Geopandas geopandas |
|
| References | () https://aydinnyunus.github.io/2025/12/27/sql-injection-geopandas/ - Exploit, Third Party Advisory | |
| References | () https://github.com/geopandas/geopandas/pull/3681 - Issue Tracking, Patch |
30 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
30 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-30 19:16
Updated : 2026-02-11 18:58
NVD link : CVE-2025-69662
Mitre link : CVE-2025-69662
CVE.ORG link : CVE-2025-69662
JSON object : View
Products Affected
geopandas
- geopandas
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
