spotipy has 3 CVEs on record between 2023 and 2025. The median CVSS is 4.5 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- spotipy 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
spotipy vulnerabilities
CVEs affecting spotipy, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-66040Low· 3.6Spotipy has a XSS vulnerability in its OAuth callback server
Spotipy has a XSS vulnerability in its OAuth callback server
▾ Sunlitspotipy · spotipyEPSS 0.16%via OSV
CVE-2025-27154HighSpotipy's cache file, containing spotify auth token, is created with overly broad permissions
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
▾ Twilightspotipy · spotipyEPSS 0.60%via OSV
CVE-2023-23608Medium· 5.4Path traversal in spotipy
Path traversal in spotipy
▾ Sunlitspotipy · spotipyEPSS 0.66%via OSV