PyPI: sqlalchemy

CVE-2019-7164

Safety vulnerability ID: SFTY-20190220-65640

Safety legacy ID: pyup.io-38497

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. https://github.com/sqlalchemy/sqlalchemy/issues/4481

Created at: Apr 24, 2026Updated at: Apr 24, 2026

Overview

SQLAlchemy vulnerable to SQL Injection via order_by parameter

Advisory

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. https://github.com/sqlalchemy/sqlalchemy/issues/4481

Affected Package

Affecting sqlalchemy package, versions
<=1.2.17
>=1.3.0b1,<=1.3.0b2

Also affects

---

How to Fix

Upgrade
sqlalchemy
to
1.2.18
1.3.0b3
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

References

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more