<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:32:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-262018</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262018</link>
      <description>EUVD-2026-262018</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262018</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66040</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66040</link>
      <description>&lt;p&gt;Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication. This issue has been patched in version 2.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication. This issue has been patched in version 2.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66040</guid>
    </item>
    <item>
      <title>GHSA-r77h-rpp9-w2xm — Spotipy has a XSS vulnerability in its OAuth callback server</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r77h-rpp9-w2xm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: spotipy&lt;/p&gt;
&lt;p&gt;### Summary
XSS vulnerability in OAuth callback server allows JavaScript injection through unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable Code:** `spotipy/oauth2.py` lines 1238-1274 (RequestHandler.do_GET)&lt;/p&gt;
&lt;p&gt;**The Problem:**
During OAuth flow, spotipy starts a local HTTP server to receive callbacks. The server reflects the `error` URL parameter directly into HTML without sanitization.&lt;/p&gt;
&lt;p&gt;**Vulnerable code at line 1255:**
```python
status = f&amp;#34;failed ({self.server.error})&amp;#34;
```&lt;/p&gt;
&lt;p&gt;**Then embedded in HTML at line 1265:**
```python
self._write(f&amp;#34;&amp;#34;&amp;#34;&amp;lt;html&amp;gt;
&amp;lt;body&amp;gt;
&amp;lt;h1&amp;gt;Authentication status: {status}&amp;lt;/h1&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;&amp;#34;&amp;#34;&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;The `error` parameter comes from URL parsing (lines 388-393) without HTML escaping, allowing script injection.&lt;/p&gt;
&lt;p&gt;**Attack Flow:**
1. User starts OAuth authentication → local server runs on `http://127.0.0.1:8080`
2. Attacker crafts malicious URL: `http://127.0.0.1:8080/?error=&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;amp;state=x`
3. User visits URL → JavaScript executes in localhost origin&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Simple Python Test:**
```python
#!/usr/bin/env python3
# poc_xss.py - Demonstrates XSS in spotipy OAuth callback&lt;/p&gt;
&lt;p&gt;import requests
from spotipy.oauth2 import start_local_http_server
import threading
import time&lt;/p&gt;
&lt;p&gt;# Start vulnerable server in background
def start_server():
    server = start_local_http_server(8080)
    server.handle_request()&lt;/p&gt;
&lt;p&gt;thread = threading.Thread(target=start_serve…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: spotipy&lt;/p&gt;
&lt;p&gt;### Summary
XSS vulnerability in OAuth callback server allows JavaScript injection through unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable Code:** `spotipy/oauth2.py` lines 1238-1274 (RequestHandler.do_GET)&lt;/p&gt;
&lt;p&gt;**The Problem:**
During OAuth flow, spotipy starts a local HTTP server to receive callbacks. The server reflects the `error` URL parameter directly into HTML without sanitization.&lt;/p&gt;
&lt;p&gt;**Vulnerable code at line 1255:**
```python
status = f&amp;#34;failed ({self.server.error})&amp;#34;
```&lt;/p&gt;
&lt;p&gt;**Then embedded in HTML at line 1265:**
```python
self._write(f&amp;#34;&amp;#34;&amp;#34;&amp;lt;html&amp;gt;
&amp;lt;body&amp;gt;
&amp;lt;h1&amp;gt;Authentication status: {status}&amp;lt;/h1&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;&amp;#34;&amp;#34;&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;The `error` parameter comes from URL parsing (lines 388-393) without HTML escaping, allowing script injection.&lt;/p&gt;
&lt;p&gt;**Attack Flow:**
1. User starts OAuth authentication → local server runs on `http://127.0.0.1:8080`
2. Attacker crafts malicious URL: `http://127.0.0.1:8080/?error=&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;amp;state=x`
3. User visits URL → JavaScript executes in localhost origin&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Simple Python Test:**
```python
#!/usr/bin/env python3
# poc_xss.py - Demonstrates XSS in spotipy OAuth callback&lt;/p&gt;
&lt;p&gt;import requests
from spotipy.oauth2 import start_local_http_server
import threading
import time&lt;/p&gt;
&lt;p&gt;# Start vulnerable server in background
def start_server():
    server = start_local_http_server(8080)
    server.handle_request()&lt;/p&gt;
&lt;p&gt;thread = threading.Thread(target=start_serve…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r77h-rpp9-w2xm</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15777-1 — python311-spotipy-2.25.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15777-1</link>
      <description>&lt;p&gt;python311-spotipy-2.25.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-spotipy-2.25.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15777-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1937 — Spotipy has a XSS vulnerability in its OAuth callback server</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1937</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: spotipy&lt;/p&gt;
&lt;p&gt;### Summary
XSS vulnerability in OAuth callback server allows JavaScript injection through unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable Code:** `spotipy/oauth2.py` lines 1238-1274 (RequestHandler.do_GET)&lt;/p&gt;
&lt;p&gt;**The Problem:**
During OAuth flow, spotipy starts a local HTTP server to receive callbacks. The server reflects the `error` URL parameter directly into HTML without sanitization.&lt;/p&gt;
&lt;p&gt;**Vulnerable code at line 1255:**
```python
status = f&amp;#34;failed ({self.server.error})&amp;#34;
```&lt;/p&gt;
&lt;p&gt;**Then embedded in HTML at line 1265:**
```python
self._write(f&amp;#34;&amp;#34;&amp;#34;&amp;lt;html&amp;gt;
&amp;lt;body&amp;gt;
&amp;lt;h1&amp;gt;Authentication status: {status}&amp;lt;/h1&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;&amp;#34;&amp;#34;&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;The `error` parameter comes from URL parsing (lines 388-393) without HTML escaping, allowing script injection.&lt;/p&gt;
&lt;p&gt;**Attack Flow:**
1. User starts OAuth authentication → local server runs on `http://127.0.0.1:8080`
2. Attacker crafts malicious URL: `http://127.0.0.1:8080/?error=&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;amp;state=x`
3. User visits URL → JavaScript executes in localhost origin&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Simple Python Test:**
```python
#!/usr/bin/env python3
# poc_xss.py - Demonstrates XSS in spotipy OAuth callback&lt;/p&gt;
&lt;p&gt;import requests
from spotipy.oauth2 import start_local_http_server
import threading
import time&lt;/p&gt;
&lt;p&gt;# Start vulnerable server in background
def start_server():
    server = start_local_http_server(8080)
    server.handle_request()&lt;/p&gt;
&lt;p&gt;thread = threading.Thread(target=start_serve…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: spotipy&lt;/p&gt;
&lt;p&gt;### Summary
XSS vulnerability in OAuth callback server allows JavaScript injection through unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable Code:** `spotipy/oauth2.py` lines 1238-1274 (RequestHandler.do_GET)&lt;/p&gt;
&lt;p&gt;**The Problem:**
During OAuth flow, spotipy starts a local HTTP server to receive callbacks. The server reflects the `error` URL parameter directly into HTML without sanitization.&lt;/p&gt;
&lt;p&gt;**Vulnerable code at line 1255:**
```python
status = f&amp;#34;failed ({self.server.error})&amp;#34;
```&lt;/p&gt;
&lt;p&gt;**Then embedded in HTML at line 1265:**
```python
self._write(f&amp;#34;&amp;#34;&amp;#34;&amp;lt;html&amp;gt;
&amp;lt;body&amp;gt;
&amp;lt;h1&amp;gt;Authentication status: {status}&amp;lt;/h1&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;&amp;#34;&amp;#34;&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;The `error` parameter comes from URL parsing (lines 388-393) without HTML escaping, allowing script injection.&lt;/p&gt;
&lt;p&gt;**Attack Flow:**
1. User starts OAuth authentication → local server runs on `http://127.0.0.1:8080`
2. Attacker crafts malicious URL: `http://127.0.0.1:8080/?error=&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;amp;state=x`
3. User visits URL → JavaScript executes in localhost origin&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;**Simple Python Test:**
```python
#!/usr/bin/env python3
# poc_xss.py - Demonstrates XSS in spotipy OAuth callback&lt;/p&gt;
&lt;p&gt;import requests
from spotipy.oauth2 import start_local_http_server
import threading
import time&lt;/p&gt;
&lt;p&gt;# Start vulnerable server in background
def start_server():
    server = start_local_http_server(8080)
    server.handle_request()&lt;/p&gt;
&lt;p&gt;thread = threading.Thread(target=start_serve…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1937</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-66040</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66040</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: spotipy, Ubuntu:26.04:LTS: spotipy&lt;/p&gt;
&lt;p&gt;Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication. This issue has been patched in version 2.25.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: spotipy, Ubuntu:26.04:LTS: spotipy&lt;/p&gt;
&lt;p&gt;Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback server that allows for JavaScript injection through the unsanitized error parameter. Attackers can execute arbitrary JavaScript in the user&amp;#39;s browser during OAuth authentication. This issue has been patched in version 2.25.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66040</guid>
    </item>
  </channel>
</rss>
