VDB
CVE-2025-66040
CVE-2025-66040
PUBLISHED
CVSS 3.5999999046325684 LOW
Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.
EPSS 0.16% · 5.1th percentile
Risk Scores
CVSS 3.1
3.5999999046325684
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.16%
5.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| spotipy-dev | spotipy | < 2.25.2 |
| PyPI | spotipy | 0 |
Timeline
- Jan 21, 1970 Security Advisory
- Nov 26, 2025 CVE Published
- Nov 27, 2025 EPSS Score
- Nov 27, 2025 Coalition ESS Score
- Nov 27, 2025 Coalition ESS Score
- Nov 27, 2025 PoC Published
- Nov 28, 2025 CVE Updated
- Dec 2, 2025 EPSS Score
- Dec 4, 2025 Coalition ESS Score
- Dec 6, 2025 EPSS Score
- Dec 11, 2025 EPSS Score
- Dec 16, 2025 EPSS Score