CVE-2025-66040

LOW

Spotipy <2.25.2 - XSS

Title source: llm
STIX 2.1

Description

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.

Scores

CVSS v3 3.6
EPSS 0.0001
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
pypi/spotipy 0 - 2.25.2PyPI
spotipy-dev/spotipy < 2.25.2
Published Nov 27, 2025
Tracked Since Feb 18, 2026