CVE-2025-69662: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-69662 is a SQL injection vulnerability in the geopandas Python library affecting all versions before 1.1.2. The flaw resides in the to_postgis() function, which is used to write GeoDataFrames to a PostgreSQL database, and allows an unauthenticated remote attacker to obtain sensitive information by injecting arbitrary SQL commands via a maliciously crafted geometry column name. The vulnerability was reported by researcher Yunus Aydın on November 26, 2025, the fix was merged on December 14, 2025, and the CVE was publicly disclosed on January 30, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (Github Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper neutralization of special elements in an SQL command (CWE-89), compounded by potential exposure of sensitive information through data queries (CWE-202). Specifically, the to_postgis() function constructs SQL statements using the geometry column name without adequate sanitization or parameterization, allowing attacker-controlled input to be interpreted as SQL rather than a literal string. Attack patterns include DROP TABLE injection, UNION SELECT injection, comment-based injection, and semicolon-based injection via the geometry column name parameter. A public write-up and proof-of-concept are available from the discovering researcher (Researcher Blog, GitHub PR #3681).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the connected PostgreSQL database, resulting in unauthorized disclosure of sensitive data stored within it. The CVSS scope is marked as "Changed," indicating that the impact extends beyond the vulnerable geopandas component to the underlying database system. Integrity and availability of the database are not directly impacted by this vulnerability, but confidentiality is rated High, meaning full data exfiltration from the PostgreSQL instance is possible (Github Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept exploit is publicly available on the researcher's blog, demonstrating the injection technique via the geometry column name parameter (Researcher Blog). No user interaction or authentication is required, and the attack is executable over the network with low complexity. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015% (3rd percentile), indicating a currently low probability of active exploitation (Github Advisory).

Exploitation steps

  1. Identify target: Locate applications that use geopandas versions prior to 1.1.2 and call to_postgis() with user-influenced geometry column names to write data to a PostgreSQL database.
  2. Craft malicious geometry column name: Prepare a payload that injects SQL into the geometry column name parameter, for example: geometry"; DROP TABLE target_table; -- or geometry" UNION SELECT sensitive_column FROM sensitive_table; --.
  3. Trigger the vulnerable function: Supply the malicious geometry column name to the to_postgis() function call, either directly (if the application exposes this parameter to user input) or indirectly through a GeoDataFrame column name that is passed unsanitized.
  4. SQL command execution: The unsanitized column name is interpolated directly into the SQL statement sent to PostgreSQL, causing the injected SQL to execute in the database context.
  5. Exfiltrate data: Use UNION-based or error-based SQL injection techniques to extract sensitive data from the PostgreSQL database, leveraging the database connection privileges of the application (Researcher Blog, GitHub PR #3681).

Indicators of compromise

  • Logs: PostgreSQL query logs showing unexpected SQL keywords (e.g., DROP TABLE, UNION SELECT, --, ;) embedded within geometry column name fields in queries originating from geopandas to_postgis() calls.
  • Logs: Application-level errors or stack traces related to malformed SQL queries generated by to_postgis(), potentially indicating injection attempts.
  • Network: Unusual or unexpected data volumes returned from PostgreSQL to the application host, which may indicate data exfiltration via UNION-based injection.
  • Database: Unexpected table drops, schema changes, or new queries accessing sensitive tables not normally queried by the geopandas application user.

Mitigation and workarounds

The primary remediation is to upgrade geopandas to version 1.1.2 or later, which includes the fix that properly sanitizes geometry column names before constructing SQL statements (GitHub PR #3681, Github Advisory). For systems that cannot be immediately patched, restrict network access to applications using geopandas, limit PostgreSQL database user privileges to the minimum required, and avoid passing user-controlled input as geometry column names to to_postgis(). Additionally, monitor PostgreSQL logs for anomalous SQL activity and consider implementing database-level access controls to limit the blast radius of any exploitation.

Community reactions

The vulnerability received coverage from The Hacker Wire shortly after disclosure, highlighting the SQL injection risk in the to_postgis() function (The Hacker Wire). The CVE appeared in community roundups such as Reddit's CVEWatch "Top 10 Trending CVEs" for early February 2026, indicating moderate community interest. Ubuntu and Debian issued security advisories addressing the vulnerability in their respective geopandas packages, and TUXEDO OS noted the update in their weekly release notes, reflecting broad Linux distribution uptake of the fix.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

python-geopandas

Affected

sid

python-geopandas: 1.1.2-1

Fixed

trixie

python-geopandas

Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management