PT-2026-105909 · Pypi · Social-Auth-Core
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Impact
The
vk-app backend accepted VK application callback data without verifying the callback signature when the auth key parameter was omitted.Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as
viewer id, access token, api id, and api result, potentially allowing authentication as an arbitrary VK user ID.The issue affects only applications using the
vk-app backend.Patches
The issue has been fixed by requiring
auth key to be present and valid before callback data is trusted.Users should upgrade to a patched version.
Fix:
Workarounds
Applications that cannot upgrade immediately should disable the
vk-app backend by removing social core.backends.vk.VKAppOAuth2 from SOCIAL AUTH AUTHENTICATION BACKENDS.There is no complete workaround while continuing to use the vulnerable backend.
Credits
Reported by @lalalala5678 through GitHub private vulnerability reporting.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Social-Auth-Core