Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-57177— social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

Quick assessment

Affected
python-social-auth social-core
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Python Social Auth 是一种社交身份验证/注册机制。在 5.0.0 版本之前,LoginRadius 后端在身份验证流程中未对 OAuth state(状态令牌)进行验证。使用该后端的应用程序存在登录 CSRF(跨站请求伪造)漏洞。攻击者可以利用此漏洞,使受害者的浏览器会话使用攻击者控制的 LoginRadius 令牌完成身份验证,从而导致受害者被认证为攻击者的 LoginRadius 身份。该漏洞仅影响使用 LoginRadius 后端的应用程序。在 5.0.0 版本中,通过为 LoginRadi

CVSS 4.3 · Medium EPSS 0.11% · P1
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-57177

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
Source: CVE Program / CVE List V5
Vulnerability Description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
python-social-auth social-core < 5.0.0 -

II. Public POCs for CVE-2026-57177

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57177

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-57177 (1)

Same Patch Batch · python-social-auth · 2026-09-24 · 5 CVEs total

CVE-2026-57178 7.4 HIGH social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
CVE-2026-57176 6.8 MEDIUM social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
CVE-2026-57175 6.4 MEDIUM social-auth-core has an Improper Authentication issue
CVE-2026-57179 4.2 MEDIUM social-auth-core has a Session Fixation issue

IV. Related Vulnerabilities

V. Comments for CVE-2026-57177

No comments yet


Leave a comment