CVE-2026-57177Medium· 4.3▾ SunlitPython Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
social-auth-core < 5.0.0Patched in:
social-auth-core 5.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57175Medium· 6.4Python Social Auth is a social authentication/registration mechanism
CVE-2026-57178High· 7.4Python Social Auth is a social authentication/registration mechanism
CVE-2026-57176Medium· 6.8Python Social Auth is a social authentication/registration mechanism
CVE-2026-57179Medium· 4.2Python Social Auth is a social authentication/registration mechanism
CVE-2026-61593High· 8.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
CVE-2017-20120Medium· 4.3A vulnerability classified as problematic was found in TrueConf Server 4.3.7