Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-66040

Опубликовано: 27 нояб. 2025
Источник: debian
EPSS Низкий

Описание

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
spotipyfixed2.25.2-1package
spotipyno-dsatrixiepackage

Примечания

  • https://github.com/spotipy-dev/spotipy/security/advisories/GHSA-r77h-rpp9-w2xm

  • https://github.com/spotipy-dev/spotipy/commit/880b92d7243dcf2b83bf31dc365a858d8b5e6767 (2.25.2)

EPSS

Процентиль: 10%
0.00035
Низкий

Связанные уязвимости

CVSS3: 3.6
ubuntu
2 месяца назад

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
nvd
2 месяца назад

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
github
2 месяца назад

Spotipy has a XSS vulnerability in its OAuth callback server

EPSS

Процентиль: 10%
0.00035
Низкий