
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69662 is a SQL injection vulnerability in the geopandas Python library affecting all versions before 1.1.2. The flaw resides in the to_postgis() function, which is used to write GeoDataFrames to a PostgreSQL database, and allows an unauthenticated remote attacker to obtain sensitive information by injecting arbitrary SQL commands via a maliciously crafted geometry column name. The vulnerability was reported by researcher Yunus Aydın on November 26, 2025, the fix was merged on December 14, 2025, and the CVE was publicly disclosed on January 30, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (Github Advisory, Red Hat Bugzilla).
The root cause is improper neutralization of special elements in an SQL command (CWE-89), compounded by potential exposure of sensitive information through data queries (CWE-202). Specifically, the to_postgis() function constructs SQL statements using the geometry column name without adequate sanitization or parameterization, allowing attacker-controlled input to be interpreted as SQL rather than a literal string. Attack patterns include DROP TABLE injection, UNION SELECT injection, comment-based injection, and semicolon-based injection via the geometry column name parameter. A public write-up and proof-of-concept are available from the discovering researcher (Researcher Blog, GitHub PR #3681).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the connected PostgreSQL database, resulting in unauthorized disclosure of sensitive data stored within it. The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable geopandas component to the underlying database system. Integrity and availability of the database are not directly impacted by this vulnerability, but confidentiality is rated High, meaning full data exfiltration from the PostgreSQL instance is possible (Github Advisory, Red Hat Bugzilla).
A proof-of-concept exploit is publicly available on the researcher's blog, demonstrating the injection technique via the geometry column name parameter (Researcher Blog). No user interaction or authentication is required, and the attack is executable over the network with low complexity. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015% (3rd percentile), indicating a currently low probability of active exploitation (Github Advisory).
to_postgis() with user-influenced geometry column names to write data to a PostgreSQL database.geometry"; DROP TABLE target_table; -- or geometry" UNION SELECT sensitive_column FROM sensitive_table; --.to_postgis() function call, either directly (if the application exposes this parameter to user input) or indirectly through a GeoDataFrame column name that is passed unsanitized.DROP TABLE, UNION SELECT, --, ;) embedded within geometry column name fields in queries originating from geopandas to_postgis() calls.to_postgis(), potentially indicating injection attempts.The primary remediation is to upgrade geopandas to version 1.1.2 or later, which includes the fix that properly sanitizes geometry column names before constructing SQL statements (GitHub PR #3681, Github Advisory). For systems that cannot be immediately patched, restrict network access to applications using geopandas, limit PostgreSQL database user privileges to the minimum required, and avoid passing user-controlled input as geometry column names to to_postgis(). Additionally, monitor PostgreSQL logs for anomalous SQL activity and consider implementing database-level access controls to limit the blast radius of any exploitation.
The vulnerability received coverage from The Hacker Wire shortly after disclosure, highlighting the SQL injection risk in the to_postgis() function (The Hacker Wire). The CVE appeared in community roundups such as Reddit's CVEWatch "Top 10 Trending CVEs" for early February 2026, indicating moderate community interest. Ubuntu and Debian issued security advisories addressing the vulnerability in their respective geopandas packages, and TUXEDO OS noted the update in their weekly release notes, reflecting broad Linux distribution uptake of the fix.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."