PT-2026-98191 · Pypi · Python Social Auth
CVE-2026-57179
·
Published
2026-09-24
·
Updated
2026-10-01
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Python Social Auth versions prior to 5.0.0
Description
The partial-pipeline resume mechanism accepts the
partial token as a bearer credential without binding it to the browser session that created it. This allows an attacker to initiate an authentication flow, obtain a valid partial token and verification data, and trick a victim's browser into resuming this attacker-controlled flow. Consequently, the victim's browser could be authenticated as the attacker's account. This issue impacts applications utilizing resumable partial pipeline steps, such as mail validation or custom steps decorated with @partial.Recommendations
Update to version 5.0.0 or later.
As a temporary workaround, disable resumable partial pipeline steps, including
mail validation and custom steps decorated with @partial.
Avoid accepting partial resume links from untrusted contexts.Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python Social Auth