PT-2025-48208 · Pypi+1 · Spotipy+1
Published
2025-11-26
·
Updated
2025-11-27
·
CVE-2025-66040
CVSS v3.1
3.6
Low
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spotipy versions prior to 2.25.2
Description
Spotipy is a Python library used for interacting with the Spotify Web API. A flaw exists in the OAuth callback server that permits JavaScript injection through an unsanitized error parameter, leading to a cross-site scripting (XSS) condition. Successful exploitation allows attackers to execute arbitrary JavaScript code within the user's browser during the OAuth authentication process.
Recommendations
Update Spotipy to version 2.25.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Spotipy