« Back to list

Spotipy Project

Spotipy Project Spotipy: vulnerabilities and CVEs

Spotipy Project Spotipy has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-27154High (8.4)0.61%—Feb 27, 2025
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created has `rw-r--r--` (644) permissions by…
CVE-2023-23608Medium (4.3)0.66%—Jan 26, 2023
Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation1
  2. T1552.001 Credentials In Files1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.