Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-66040

Опубликовано: 27 нояб. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 3.6

Описание

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

plucky

needs-triage

questing

needs-triage

upstream

needs-triage

Показывать по

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
nvd
4 дня назад

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
debian
4 дня назад

Spotipy is a Python library for the Spotify Web API. Prior to version ...

3.6 Low

CVSS3