PT-2026-98188 · Pypi · Python Social Auth

CVE-2026-57176

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Python Social Auth versions prior to 5.0.0
Description The Vend OAuth2 backend uses only the numeric user id as the social-auth UID. In applications where multiple Vend shops authenticate, users from different shops who share the same internal Vend user ID can collide in the social-auth association table. This allows a user from one shop to be authenticated as a local account previously associated with the same numeric user id from a different shop.
Recommendations Update to version 5.0.0 or later. Restrict the Vend OAuth2 backend to a single trusted Vend shop. Disable the Vend backend by removing it from SOCIAL AUTH AUTHENTICATION BACKENDS if Vend authentication is not required.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57176
GHSA-FP7W-M676-W7GC

Affected Products

Python Social Auth