Python Social Auth 是一个社交认证/注册机制。在 5.0.0 版本之前,SAML 后端在断言消费者服务(Assertion Consumer Service, ACS)端点接收 SAML 响应时,未验证这些响应是否与先前发出的 匹配。使用该库中 SAML 账户关联功能的用户可能遭受攻击:具有受信任身份提供者(IdP)上有效账户的攻击者,可以将其 SAML 身份与已登录受害者的本地账户进行关联。随后,攻击者可通过 SAML 完成认证,进而访问受害者的账户。 该漏洞影响使用 SAML 后端并结合经认证
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| python-social-auth | social-core | < 5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57178 | 7.4 HIGH | social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing |
| CVE-2026-57176 | 6.8 MEDIUM | social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend |
| CVE-2026-57177 | 4.3 MEDIUM | social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend |
| CVE-2026-57179 | 4.2 MEDIUM | social-auth-core has a Session Fixation issue |
No comments yet