CVE-2026-57179Medium· 4.2▾ SunlitPython Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted partial_token as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as mail_validation or custom steps decorated with @partial. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
social-auth-core < 5.0.0Patched in:
social-auth-core 5.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57175Medium· 6.4Python Social Auth is a social authentication/registration mechanism
CVE-2026-57178High· 7.4Python Social Auth is a social authentication/registration mechanism
CVE-2026-57176Medium· 6.8Python Social Auth is a social authentication/registration mechanism
CVE-2026-57177Medium· 4.3Python Social Auth is a social authentication/registration mechanism
CVE-2026-61592High· 7.4djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
CVE-2024-23679Critical· 9.8Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue