PT-2026-105912 · Pypi · Social-Auth-Core
Published
2026-10-01
·
Updated
2026-10-01
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Impact
The partial-pipeline resume mechanism accepted
partial token as a bearer credential without binding it to the browser session that created it.Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account.
The issue affects applications using partial pipeline steps such as
mail validation or custom steps decorated with @partial.Patches
The issue has been fixed by binding partial pipeline resumes to the originating browser session.
Users should upgrade to a patched version.
Fix:
- https://github.com/python-social-auth/social-core/pull/1816
- https://github.com/python-social-auth/social-docs/pull/444
- https://github.com/python-social-auth/social-app-django/pull/1009
Workarounds
Applications that cannot upgrade immediately should disable resumable partial pipeline steps, including
mail validation and custom steps decorated with @partial.If those flows are required, applications should avoid accepting partial resume links from untrusted contexts until a patched version can be deployed.
There is no complete workaround while continuing to use the vulnerable partial-pipeline resume mechanism.
Credits
Reported through GitHub private vulnerability reporting by Liyi Zhou, Ziyue Wang, Strick, Maurice, and Chenchen Yu from the University of Sydney security research team.
Reporter references:
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Social-Auth-Core