CVE-2025-47928 affects the Spotipy Python library, specifically its GitHub Actions workflow. It allows attackers to execute untrusted code from a forked pull request with full access to the base repository's secrets, including GITHUB_TOKEN, SPOTIPY_CLIENT_ID, and SPOTIPY_CLIENT_SECRET. This critical vulnerability (CVSS 9.1) has a low attack complexity and can lead to complete repository takeover due to the GITHUB_TOKEN's write privileges. While there is no known active exploitation or public exploit code, the vulnerability has garnered community discussion and media coverage, indicating awareness of its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Spotipy-Dev | Spotipy | = 4f5759dbfb4506c7b6280572a4db1aabc1ac778dCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.