spotipy vulnerabilities
CVEs whose affected-version data names the spotipy package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-66040Low· 3.6Spotipy has a XSS vulnerability in its OAuth callback server
Spotipy has a XSS vulnerability in its OAuth callback server
▾ Sunlitspotipy · spotipyEPSS 0.16%via OSV
CVE-2025-27154HighSpotipy's cache file, containing spotify auth token, is created with overly broad permissions
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
▾ Twilightspotipy · spotipyEPSS 0.60%via OSV
CVE-2023-23608Medium· 5.4Path traversal in spotipy
Path traversal in spotipy
▾ Sunlitspotipy · spotipyEPSS 0.66%via OSV