PT-2026-105909 · Pypi · Social-Auth-Core

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Impact

The vk-app backend accepted VK application callback data without verifying the callback signature when the auth key parameter was omitted.
Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as viewer id, access token, api id, and api result, potentially allowing authentication as an arbitrary VK user ID.
The issue affects only applications using the vk-app backend.

Patches

The issue has been fixed by requiring auth key to be present and valid before callback data is trusted.
Users should upgrade to a patched version.
Fix:

Workarounds

Applications that cannot upgrade immediately should disable the vk-app backend by removing social core.backends.vk.VKAppOAuth2 from SOCIAL AUTH AUTHENTICATION BACKENDS.
There is no complete workaround while continuing to use the vulnerable backend.

Credits

Reported by @lalalala5678 through GitHub private vulnerability reporting.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4165

Affected Products

Social-Auth-Core