PT-2025-48208 · Pypi+1 · Spotipy+1

Published

2025-11-26

·

Updated

2025-11-27

·

CVE-2025-66040

CVSS v3.1

3.6

Low

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spotipy versions prior to 2.25.2
Description Spotipy is a Python library used for interacting with the Spotify Web API. A flaw exists in the OAuth callback server that permits JavaScript injection through an unsanitized error parameter, leading to a cross-site scripting (XSS) condition. Successful exploitation allows attackers to execute arbitrary JavaScript code within the user's browser during the OAuth authentication process.
Recommendations Update Spotipy to version 2.25.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66040
GHSA-R77H-RPP9-W2XM
OPENSUSE-SU-2025:15777-1

Affected Products

Debian
Spotipy