Python Social Auth 是一种社交身份验证/注册机制。在 5.0.0 版本之前,LoginRadius 后端在身份验证流程中未对 OAuth state(状态令牌)进行验证。使用该后端的应用程序存在登录 CSRF(跨站请求伪造)漏洞。攻击者可以利用此漏洞,使受害者的浏览器会话使用攻击者控制的 LoginRadius 令牌完成身份验证,从而导致受害者被认证为攻击者的 LoginRadius 身份。该漏洞仅影响使用 LoginRadius 后端的应用程序。在 5.0.0 版本中,通过为 LoginRadi
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| python-social-auth | social-core | < 5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57178 | 7.4 HIGH | social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing |
| CVE-2026-57176 | 6.8 MEDIUM | social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend |
| CVE-2026-57175 | 6.4 MEDIUM | social-auth-core has an Improper Authentication issue |
| CVE-2026-57179 | 4.2 MEDIUM | social-auth-core has a Session Fixation issue |
No comments yet