PT-2026-105909 · Pypi · Social-Auth-Core
Published
2026-10-01
·
Updated
2026-10-01
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Impact
The
vk-app backend accepted VK application callback data without verifying the callback signature when the auth key parameter was omitted.Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as
viewer id, access token, api id, and api result, potentially allowing authentication as an arbitrary VK user ID.The issue affects only applications using the
vk-app backend.Patches
The issue has been fixed by requiring
auth key to be present and valid before callback data is trusted.Users should upgrade to a patched version.
Fix:
Workarounds
Applications that cannot upgrade immediately should disable the
vk-app backend by removing social core.backends.vk.VKAppOAuth2 from SOCIAL AUTH AUTHENTICATION BACKENDS.There is no complete workaround while continuing to use the vulnerable backend.
Credits
Reported by @lalalala5678 through GitHub private vulnerability reporting.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Social-Auth-Core