SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
"https://github.com/pypa/advisory-database/blob/main/vulns/sqlalchemy/PYSEC-2019-124.yaml"