HIGH8.6
PYSEC-2026-62
Quick fix
PYSEC-2026-62 — geopandas: upgrade to the fixed version with the command below.
pip install --upgrade 'geopandas>=1.1.2'Details
SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
Are you affected?
Enter the version of the package you're using.