Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-57179— social-auth-core has a Session Fixation issue

Quick assessment

Affected
python-social-auth social-core
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Python Social Auth 是一个社会化认证/注册机制。在 5.0.0 版本之前,部分流程恢复机制接受 作为承载凭证(bearer credential),但并未将其与创建该凭证的浏览器会话绑定。使用可恢复部分流程步骤的应用程序,可能允许攻击者启动认证流程、获取有效的部分令牌和验证数据,并致使受害者的浏览器恢复由该攻击者控制的流程。这可能导致受害者的浏览器被认证为攻击者的账户。此问题会影响使用诸如 部分流程步骤或经 装饰器自定义的部分流程步骤的应用程序。该问题已在 5.0.0 版本中通过将对部分流程的恢复

CVSS 4.2 · Medium EPSS 0.16% · P4
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-57179

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
social-auth-core has a Session Fixation issue
Source: CVE Program / CVE List V5
Vulnerability Description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
会话固定
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
python-social-auth social-core < 5.0.0 -

II. Public POCs for CVE-2026-57179

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57179

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-57179 (1)

Same Patch Batch · python-social-auth · 2026-09-24 · 5 CVEs total

CVE-2026-57178 7.4 HIGH social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
CVE-2026-57176 6.8 MEDIUM social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
CVE-2026-57175 6.4 MEDIUM social-auth-core has an Improper Authentication issue
CVE-2026-57177 4.3 MEDIUM social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

IV. Related Vulnerabilities

V. Comments for CVE-2026-57179

No comments yet


Leave a comment