PT-2026-98191 · Pypi · Python Social Auth

CVE-2026-57179

·

Published

2026-09-24

·

Updated

2026-10-01

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Python Social Auth versions prior to 5.0.0
Description The partial-pipeline resume mechanism accepts the partial token as a bearer credential without binding it to the browser session that created it. This allows an attacker to initiate an authentication flow, obtain a valid partial token and verification data, and trick a victim's browser into resuming this attacker-controlled flow. Consequently, the victim's browser could be authenticated as the attacker's account. This issue impacts applications utilizing resumable partial pipeline steps, such as mail validation or custom steps decorated with @partial.
Recommendations Update to version 5.0.0 or later. As a temporary workaround, disable resumable partial pipeline steps, including mail validation and custom steps decorated with @partial. Avoid accepting partial resume links from untrusted contexts.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57179
GHSA-VQG6-3FW6-J9JG
PYSEC-2026-4168

Affected Products

Python Social Auth