Python Social Auth 是一个社会化认证/注册机制。在 5.0.0 版本之前,部分流程恢复机制接受 作为承载凭证(bearer credential),但并未将其与创建该凭证的浏览器会话绑定。使用可恢复部分流程步骤的应用程序,可能允许攻击者启动认证流程、获取有效的部分令牌和验证数据,并致使受害者的浏览器恢复由该攻击者控制的流程。这可能导致受害者的浏览器被认证为攻击者的账户。此问题会影响使用诸如 部分流程步骤或经 装饰器自定义的部分流程步骤的应用程序。该问题已在 5.0.0 版本中通过将对部分流程的恢复
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| python-social-auth | social-core | < 5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57178 | 7.4 HIGH | social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing |
| CVE-2026-57176 | 6.8 MEDIUM | social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend |
| CVE-2026-57175 | 6.4 MEDIUM | social-auth-core has an Improper Authentication issue |
| CVE-2026-57177 | 4.3 MEDIUM | social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend |
No comments yet