[Git][security-tracker-team/security-tracker][master] Add CVE-2025-66040/spotipy

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Nov 27 08:21:43 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
07a8a4d2 by Salvatore Bonaccorso at 2025-11-27T09:21:15+01:00
Add CVE-2025-66040/spotipy

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,7 +3,9 @@ CVE-2025-7820 (The SKT PayPal for WooCommerce plugin for WordPress is vulnerable
 CVE-2025-66314 (Improper Privilege Management vulnerability in ZTE ElasticNet UME R32  ...)
 	NOT-FOR-US: ZTE
 CVE-2025-66040 (Spotipy is a Python library for the Spotify Web API. Prior to version  ...)
-	TODO: check
+	- spotipy <unfixed>
+	NOTE: https://github.com/spotipy-dev/spotipy/security/advisories/GHSA-r77h-rpp9-w2xm
+	NOTE: https://github.com/spotipy-dev/spotipy/commit/880b92d7243dcf2b83bf31dc365a858d8b5e6767 (2.25.2)
 CVE-2025-66035 (Angular is a development platform for building mobile and desktop web  ...)
 	TODO: check
 CVE-2025-66031 (Forge (also called `node-forge`) is a native implementation of Transpo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07a8a4d295b8519d32e31e3ba5101a4c5d85871d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07a8a4d295b8519d32e31e3ba5101a4c5d85871d
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251127/4c8f4e48/attachment.htm>


More information about the debian-security-tracker-commits mailing list