© 2025-2026 PySpect
First version without a known vulnerability: 2.25.2
Spotipy has a XSS vulnerability in its OAuth callback server
Fixed in: 2.25.2
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
Fixed in: 2.25.1
Path traversal in spotipy
Fixed in: 2.22.1