Логотип exploitDog
bind:CVE-2025-66040
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66040

Количество 4

Количество 4

ubuntu логотип

CVE-2025-66040

2 месяца назад

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
EPSS: Низкий
nvd логотип

CVE-2025-66040

2 месяца назад

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
EPSS: Низкий
debian логотип

CVE-2025-66040

2 месяца назад

Spotipy is a Python library for the Spotify Web API. Prior to version ...

CVSS3: 3.6
EPSS: Низкий
github логотип

GHSA-r77h-rpp9-w2xm

2 месяца назад

Spotipy has a XSS vulnerability in its OAuth callback server

CVSS3: 3.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-66040

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-66040

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

CVSS3: 3.6
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-66040

Spotipy is a Python library for the Spotify Web API. Prior to version ...

CVSS3: 3.6
0%
Низкий
2 месяца назад
github логотип
GHSA-r77h-rpp9-w2xm

Spotipy has a XSS vulnerability in its OAuth callback server

CVSS3: 3.6
0%
Низкий
2 месяца назад

Уязвимостей на страницу