SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community
Latest patch release: 0.9.10
Latest minor release: --
Latest major release: 2.0.37
Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.
MIT - MIT License