PT-2026-98188 · Pypi · Python Social Auth
CVE-2026-57176
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Python Social Auth versions prior to 5.0.0
Description
The Vend OAuth2 backend uses only the numeric
user id as the social-auth UID. In applications where multiple Vend shops authenticate, users from different shops who share the same internal Vend user ID can collide in the social-auth association table. This allows a user from one shop to be authenticated as a local account previously associated with the same numeric user id from a different shop.Recommendations
Update to version 5.0.0 or later.
Restrict the Vend OAuth2 backend to a single trusted Vend shop.
Disable the Vend backend by removing it from
SOCIAL AUTH AUTHENTICATION BACKENDS if Vend authentication is not required.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python Social Auth