Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4523-1 | python-geopandas security update |
Github GHSA |
GHSA-6497-prx7-gpmq | geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure |
Ubuntu USN |
USN-8083-1 | GeoPandas vulnerability |
Wed, 22 Apr 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized SQL Injection via geopandas to_postgis() |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:geopandas:geopandas:*:*:*:*:*:python:*:* |
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geopandas
Geopandas geopandas |
|
| Vendors & Products |
Geopandas
Geopandas geopandas |
Fri, 30 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Fri, 30 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-21T18:22:26.627Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69662
Updated: 2026-04-21T18:22:26.627Z
Status : Modified
Published: 2026-01-30T19:16:11.967
Modified: 2026-04-21T19:16:16.373
Link: CVE-2025-69662
No data.
OpenCVE Enrichment
Updated: 2026-04-22T12:15:16Z
Debian DLA
Github GHSA
Ubuntu USN