Spotify's vulnerability footprint centers on its music streaming platform and the Luigi data-processing framework, reflecting a narrowly scoped product portfolio. The observed weakness classes—cross-site request forgery and OS command injection—point to web-application and data-pipeline input handling as the recurring exposure vectors; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spotify over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1167HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is required to exploit this vu | Apr 19, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-1000843HIGH Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vul | Dec 20, 2018 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spotify.
Media articles that mention a CVE ID that affects a product developed by Spotify — matched by CVE ID, not by vendor name.