VDB

CVE-2025-66040

CVE-2025-66040 PUBLISHED CVSS 3.5999999046325684 LOW

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

EPSS 0.16% · 5.1th percentile

Risk Scores

CVSS 3.1
3.5999999046325684
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.16%
5.1th percentile

Affected Products

VendorProductVersions
spotipy-devspotipy< 2.25.2
PyPIspotipy0

Timeline

  • Jan 21, 1970 Security Advisory
  • Nov 26, 2025 CVE Published
  • Nov 27, 2025 EPSS Score
  • Nov 27, 2025 Coalition ESS Score
  • Nov 27, 2025 Coalition ESS Score
  • Nov 27, 2025 PoC Published
  • Nov 28, 2025 CVE Updated
  • Dec 2, 2025 EPSS Score
  • Dec 4, 2025 Coalition ESS Score
  • Dec 6, 2025 EPSS Score
  • Dec 11, 2025 EPSS Score
  • Dec 16, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›