HIGHPyPI
GHSA-pwhh-q4h6-w599· CVE-2025-27154, PYSEC-2026-1936Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
Modified: 9/10/2026
package
pkg:pypi/spotipy
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
Modified: 9/10/2026
Path traversal in spotipy
Modified: 9/10/2026
Spotipy has a XSS vulnerability in its OAuth callback server
Modified: 7/7/2026
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
Modified: 7/7/2026
Spotipy has a XSS vulnerability in its OAuth callback server
Modified: 7/7/2026
Path traversal in spotipy
Modified: 7/7/2026