CVE-2025-27154 is a critical vulnerability affecting Spotipy, a Python library for the Spotify Web API, specifically in versions prior to 2.25.1. The CacheHandler class creates authentication token cache files with overly permissive default permissions (644), allowing unauthorized reading by other users or processes on the same machine. This can lead to the exposure of Spotify authentication tokens, enabling attackers to perform administrative actions on the associated Spotify account, depending on the token's granted scope. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe impact with high confidentiality, integrity, and availability implications, and can be exploited remotely with low attack complexity. While the EPSS score is low, suggesting a lower likelihood of exploitation compared to many CVEs, the FAUCET Risk Score is high at 87/100. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.25.1CPE matchmatch criteria | cpe:2.3:a:spotipy_project:spotipy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.