Passing concatenated strings to Connection/Session.execute() or Engine.execute() bypasses SQLAlchemy's bound parameters and produces SQL injection.
text() marks a raw SQL fragment; building that fragment with f-strings or concatenation instead of bound :params makes it injectable even inside otherwise-ORM code.
We use cookies to enhance your experience. Learn more