PT-2026-98189 · Pypi · Python Social Auth
CVE-2026-57177
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Python Social Auth versions prior to 5.0.0
Description
The LoginRadius backend fails to validate the OAuth state during the authentication flow. This leads to a login Cross-Site Request Forgery (CSRF), where an attacker can force a victim's browser session to authenticate using a token controlled by the attacker. Consequently, the victim becomes authenticated as the attacker's LoginRadius identity. This issue specifically affects applications utilizing the LoginRadius backend.
Recommendations
Update to version 5.0.0 or later.
As a temporary workaround, disable the LoginRadius backend by removing it from
SOCIAL AUTH AUTHENTICATION BACKENDS.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python Social Auth