CVE-2025-69662: Geopandas

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.

Affected products

  • Geopandas Geopandas: before 1.1.2 (fixed in 1.1.2)

Published 2026-01-30. Last modified 2026-06-17.