PT-2026-98190 · Pypi · Python Social Auth

CVE-2026-57178

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Python Social Auth versions prior to 5.0.0
Description The vk-app backend fails to verify the callback signature when the auth key parameter is omitted. This allows an attacker to provide unsigned, controlled data that the application treats as a verified VK identity. By manipulating callback fields such as viewer id, access token, api id, and api result, an attacker could potentially authenticate as any arbitrary VK user ID. This issue specifically affects applications utilizing the vk-app backend.
Recommendations Update to version 5.0.0 or later. As a temporary workaround, disable the vk-app backend by removing social core.backends.vk.VKAppOAuth2 from SOCIAL AUTH AUTHENTICATION BACKENDS.

Exploit

Fix

Improper Authentication

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57178
GHSA-3C93-F73F-QC9H

Affected Products

Python Social Auth