SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community
Latest patch release: 1.2.19
Latest minor release: 1.4.54
Latest major release: 2.0.37
Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.
MIT - MIT License