VDB

GCVE-110-PYPI-2026-015394

GCVE-110-PYPI-2026-015394
Advisory Published
Vulnetix · Advisory published July 22, 2026
[IOC-STIX-MATCH] Malicious domain open.spotify.com — referenced in deezer-downloader/setup.py — matched: server_time_url = 'https://open.spotify.com/api/server-time'

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
pypideezer-downloader* (affected)

References

advisory
web

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›