Use marshmallow validate field to check for special characters to protect against SQL injection attacks. Check this - https://github.com/marshmallow-code/marshmallow/issues/167