VDB
CVE-2025-27154
CVE-2025-27154
PUBLISHED
CVSS 8.399999618530273 HIGH
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
EPSS 0.60% · 46.5th percentile
Risk Scores
CVSS 4.0
8.399999618530273
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.60%
46.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| spotipy-dev | spotipy | < 2.25.1 |
| spotipy_project | spotipy | 0 |
| PyPI | spotipy | 0 |
Timeline
- Jan 21, 1970 Security Advisory
- Feb 19, 2025 CVE ID Reserved
- Feb 27, 2025 CVE Published
- Feb 27, 2025 CVE Updated
- Feb 28, 2025 EPSS Score
- Feb 28, 2025 Coalition ESS Score
- Mar 3, 2025 PoC Published
- Mar 3, 2025 PoC Published
- Mar 3, 2025 PoC Published
- Mar 14, 2025 EPSS Score
- Mar 17, 2025 PoC Published
- Mar 29, 2025 EPSS Score
References
- https://github.com/spotipy-dev/spotipy/commit/1ca453f6ef87a2a9e9876f52b6cb38d13532ccf2 url
- https://github.com/spotipy-dev/spotipy/blob/master/spotipy/cache_handler.py#L93-L98 url
- https://github.com/spotipy-dev/spotipy/releases/tag/2.25.1 url
- https://github.com/spotipy-dev/spotipy/security/advisories/GHSA-pwhh-q4h6-w599 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-27154 advisory
- https://github.com/spotipy-dev/spotipy package