{"id":"CVE-2025-61783","aliases":["GHSA-wv4w-6qv2-qqfg","PYSEC-2026-1932"],"title":"Python Social Auth - Django has unsafe account association ","summary":"Python Social Auth - Django has unsafe account association ","severity":"medium","vendor":"social-auth-app-django","product":"social-auth-app-django","ecosystem":"pip","affected":["social-auth-app-django < 5.6.0"],"patched":["social-auth-app-django 5.6.0"],"published":"2025-10-09","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wv4w-6qv2-qqfg","references":[{"url":"https://github.com/python-social-auth/social-app-django/security/advisories/GHSA-wv4w-6qv2-qqfg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61783"},{"url":"https://github.com/python-social-auth/social-app-django/issues/220"},{"url":"https://github.com/python-social-auth/social-app-django/issues/231"},{"url":"https://github.com/python-social-auth/social-app-django/issues/634"},{"url":"https://github.com/python-social-auth/social-app-django/pull/803"},{"url":"https://github.com/python-social-auth/social-app-django/commit/10c80e2ebabeccd4e9c84ad0e16e1db74148ed4c"},{"url":"https://github.com/python-social-auth/social-app-django"}],"tags":["osv","pip"],"epss":0.00424,"epssPercentile":0.36312,"ingestedAt":"2026-07-08T18:25:53.904Z","slug":"CVE-2025-61783","body":"## Overview\n\n### Impact\n\nUpon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses.\n\n### Patches\n\n* https://github.com/python-social-auth/social-app-django/pull/803\n\n### Workarounds\n\nReview the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.\n\n## Affected packages\n\n- `social-auth-app-django < 5.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `social-auth-app-django 5.6.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}