{"id":"CVE-2023-23608","aliases":["GHSA-q764-g6fm-555v","PYSEC-2026-926"],"url":"https://o3.security/vulnerability/CVE-2023-23608","summary":"spotipy Path traversal vulnerability that may lead to type confusion in URI handling code","details":"### Summary\nIf a malicious URI is passed to the library, the library can be tricked into performing an operation on a different API endpoint than intended.\n\n### Details\nThe [code Spotipy uses to parse URIs and URLs ](https://github.com/spotipy-dev/spotipy/blob/master/spotipy/client.py#L1942) accepts user data too liberally which allows a malicious user to insert arbitrary characters into the path that is used for API requests. Because it is possible to include `..`, an attacker can redirect for example a track lookup via `spotifyApi.track()` to an arbitrary API endpoint like playlists, but this is possible for other endpoints as well.\n\nBefore the security advisory feature was enabled on GitHub, I was already in contact with Stéphane Bruckert via e-mail, and he asked me to look into a potential fix. \n\nMy recommendation is to perform stricter parsing of URLs and URIs, which I implemented in the patch included at the end of the report. If you prefer, I can also invite you to a private fork of the repository.\n\n### Impact\nThe impact of this vulnerability depends heavily on what operations a client application performs when it handles a URI from a user and how it uses the responses it receives from the API.\n","published":"2023-01-24T02:39:32.471Z","modified":"2026-08-12T03:51:19.934608968Z","cvss":{"score":0,"severity":"NONE","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"spotipy","fixedVersion":"2.22.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/23xxx/CVE-2023-23608.json"},{"type":"ADVISORY","url":"https://github.com/spotipy-dev/spotipy/security/advisories/GHSA-q764-g6fm-555v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-23608"},{"type":"PACKAGE","url":"https://github.com/spotipy-dev/spotipy"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.934608968Z"}}