PT-2026-98190 · Pypi · Python Social Auth
CVE-2026-57178
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Python Social Auth versions prior to 5.0.0
Description
The
vk-app backend fails to verify the callback signature when the auth key parameter is omitted. This allows an attacker to provide unsigned, controlled data that the application treats as a verified VK identity. By manipulating callback fields such as viewer id, access token, api id, and api result, an attacker could potentially authenticate as any arbitrary VK user ID. This issue specifically affects applications utilizing the vk-app backend.Recommendations
Update to version 5.0.0 or later.
As a temporary workaround, disable the
vk-app backend by removing social core.backends.vk.VKAppOAuth2 from SOCIAL AUTH AUTHENTICATION BACKENDS.Exploit
Fix
Improper Authentication
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Python Social Auth