<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:36:21.490419+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-66040</id>
    <title>CVE-2025-66040 — Spotipy has a XSS vulnerability in OAuth callback server</title>
    <updated>2026-10-02T19:36:21.492397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> spotipy-dev spotipy</p>
<p>Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication. This issue has been patched in version 2.25.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-66040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r77h-rpp9-w2xm</id>
    <title>GHSA-r77h-rpp9-w2xm — Spotipy has a XSS vulnerability in its OAuth callback server</title>
    <updated>2026-10-02T19:36:21.492465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: spotipy</p>
<p>### Summary
XSS vulnerability in OAuth callback server allows JavaScript injection through unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user's browser during OAuth authentication.</p>
<p>### Details
**Vulnerable Code:** `spotipy/oauth2.py` lines 1238-1274 (RequestHandler.do_GET)</p>
<p>**The Problem:**
During OAuth flow, spotipy starts a local HTTP server to receive callbacks. The server reflects the `error` URL parameter directly into HTML without sanitization.</p>
<p>**Vulnerable code at line 1255:**
```python
status = f"failed ({self.server.error})"
```</p>
<p>**Then embedded in HTML at line 1265:**
```python
self._write(f"""&lt;html&gt;
&lt;body&gt;
&lt;h1&gt;Authentication status: {status}&lt;/h1&gt;
&lt;/body&gt;
&lt;/html&gt;""")
```</p>
<p>The `error` parameter comes from URL parsing (lines 388-393) without HTML escaping, allowing script injection.</p>
<p>**Attack Flow:**
1. User starts OAuth authentication → local server runs on `http://127.0.0.1:8080`
2. Attacker crafts malicious URL: `http://127.0.0.1:8080/?error=&lt;script&gt;alert(1)&lt;/script&gt;&amp;state=x`
3. User visits URL → JavaScript executes in localhost origin</p>
<p>### PoC</p>
<p>**Simple Python Test:**
```python
#!/usr/bin/env python3
# poc_xss.py - Demonstrates XSS in spotipy OAuth callback</p>
<p>import requests
from spotipy.oauth2 import start_local_http_server
import threading
import time</p>
<p># Start vulnerable server in background
def start_server():
    server = start_local_http_server(8080)
    server.handle_request()</p>
<p>thread = threading.Thread(target=start_serve…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r77h-rpp9-w2xm"/>
  </entry>
</feed>
