This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2025-12-08 21:19:55 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
These are the vulnerabilities relating to the commit you have selected:
| VuXML ID | Description |
|---|---|
| 8acfcfdc-d27c-11f0-8512-b0416f0c4c67 | spotipy -- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') https://github.com/spotipy-dev/spotipy/security/advisories/GHSA-r77h-rpp9-w2xm reports:
Discovery 2025-11-26 Entry 2025-12-06 py310-spotipy py311-spotipy py312-spotipy py313-spotipy py313t-spotipy py314-spotipy < 2.25.2 CVE-2025-66040 https://cveawg.mitre.org/api/cve/CVE-2025-66040 |
| 475d1968-f99d-11ef-b382-b0416f0c4c67 | Spotipy -- Spotipy's cache file, containing spotify auth token, is created with overly broad permissions security-advisories@github.com reports:
Discovery 2025-02-27 Entry 2025-03-05 py38-spotipy py39-spotipy py310-spotipy py311-spotipy < 2.25.1 CVE-2025-27154 https://nvd.nist.gov/vuln/detail/CVE-2025-27154 |