CVE-2026-57178High· 7.4▾ TwilightPython Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the vk-app backend accepted VK application callback data without verifying the callback signature when the auth_key parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as viewer_id, access_token, api_id, and api_result, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the vk-app backend. The issue has been fixed in version 5.0.0 by requiring auth_key to be present and valid before callback data is trusted.
social-core < 5.0.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57175Medium· 6.4social-auth-core has an Improper Authentication issue
CVE-2026-57176Medium· 6.8social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
CVE-2026-57177Medium· 4.3social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
CVE-2026-57179Medium· 4.2social-auth-core has a Session Fixation issue
CVE-2026-48526High· 7.4PyJWT is a JSON Web Token implementation in Python
CVE-2023-49105Critical· 9.8An issue was discovered in ownCloud owncloud/core before 10.13.1