Vulnerabilities

Summary — last 7 days

New vulnerabilities2,625▼ 312 vs. last week
Critical / high1,347▲ 72 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)61▼ 466 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredLow (3.6)0.16%—SpotipyAI11/27/20256/17/2026
Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth…
DeferredCritical (9.1)0.60%—SpotipyAI5/15/20256/17/2026
Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` followed by the checking out the head.sha of a forked PR can be exploited by attackers, since untrusted code can be executed having full…
AnalyzedHigh (8.4)0.61%—Spotipy Project Spotipy2/27/20256/17/2026
Spotipy is a lightweight Python library for the Spotify Web API. The `CacheHandler` class creates a cache file to store the auth token. Prior to version 2.25.1, the file created has `rw-r--r--` (644) permissions by default, when it could be locked down to `rw-------` (600) permissions. This leads to overly broad…
ModifiedMedium (4.3)0.66%—Spotipy Project Spotipy1/26/20236/17/2026
Spotipy is a light weight Python library for the Spotify Web API. In versions prior to 2.22.1, if a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended. The code Spotipy uses to parse URIs and URLs allows an attacker to insert…