Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r77h-rpp9-w2xm | Spotipy has a XSS vulnerability in its OAuth callback server |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spotipy Project
Spotipy Project spotipy |
|
| Vendors & Products |
Spotipy Project
Spotipy Project spotipy |
Wed, 26 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2. | |
| Title | Spotipy has a XSS vulnerability in OAuth callback server | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-28T15:25:40.139Z
Reserved: 2025-11-21T01:08:02.615Z
Link: CVE-2025-66040
Updated: 2025-11-28T15:25:26.909Z
Status : Awaiting Analysis
Published: 2025-11-27T00:15:55.343
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-66040
No data.
OpenCVE Enrichment
Updated: 2025-11-27T16:26:14Z
Github GHSA