Python Social Auth 是一个社交身份认证/注册机制。在 5.0.0 版本之前, 后端在处理 VK 应用程序的回调数据时,若未提供 参数,则不会验证回调数据的签名。使用此后端的應用可能會將攻擊者控制的、未签名的数据视为已验证的 VK 身份。攻击者可以操控回调字段(如 、 、 和 ),从而可能以任意 VK 用户 ID 进行身份认证。该问题仅影响使用了 后端的應用。此漏洞已在 5.0.0 版本中修复,修复方式为:在信任回调数据之前,必须要求 参数存在且有效。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| python-social-auth | social-core | < 5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57176 | 6.8 MEDIUM | social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend |
| CVE-2026-57175 | 6.4 MEDIUM | social-auth-core has an Improper Authentication issue |
| CVE-2026-57177 | 4.3 MEDIUM | social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend |
| CVE-2026-57179 | 4.2 MEDIUM | social-auth-core has a Session Fixation issue |
No comments yet