Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-57178— social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

Quick assessment

Affected
python-social-auth social-core
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Python Social Auth 是一个社交身份认证/注册机制。在 5.0.0 版本之前, 后端在处理 VK 应用程序的回调数据时,若未提供 参数,则不会验证回调数据的签名。使用此后端的應用可能會將攻擊者控制的、未签名的数据视为已验证的 VK 身份。攻击者可以操控回调字段(如 、 、 和 ),从而可能以任意 VK 用户 ID 进行身份认证。该问题仅影响使用了 后端的應用。此漏洞已在 5.0.0 版本中修复,修复方式为:在信任回调数据之前,必须要求 参数存在且有效。

CVSS 7.4 · High EPSS 0.16% · P5
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-57178

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
Source: CVE Program / CVE List V5
Vulnerability Description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
python-social-auth social-core < 5.0.0 -

II. Public POCs for CVE-2026-57178

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57178

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-57178 (1)

Same Patch Batch · python-social-auth · 2026-09-24 · 5 CVEs total

CVE-2026-57176 6.8 MEDIUM social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
CVE-2026-57175 6.4 MEDIUM social-auth-core has an Improper Authentication issue
CVE-2026-57177 4.3 MEDIUM social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
CVE-2026-57179 4.2 MEDIUM social-auth-core has a Session Fixation issue

IV. Related Vulnerabilities

V. Comments for CVE-2026-57178

No comments yet


Leave a comment