Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spotipy Project
Spotipy Project spotipy |
|
| Vendors & Products |
Spotipy Project
Spotipy Project spotipy |
Wed, 26 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2. | |
| Title | Spotipy has a XSS vulnerability in OAuth callback server | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-26T23:14:44.795Z
Updated: 2025-11-26T23:14:44.795Z
Reserved: 2025-11-21T01:08:02.615Z
Link: CVE-2025-66040
No data.
Status : Received
Published: 2025-11-27T00:15:55.343
Modified: 2025-11-27T00:15:55.343
Link: CVE-2025-66040
No data.