CVE-2026-57178

Summary

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the vk-app backend accepted VK application callback data without verifying the callback signature when the auth_key parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as viewer_id, access_token, api_id, and api_result, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the vk-app backend. The issue has been fixed in version 5.0.0 by requiring auth_key to be present and valid before callback data is trusted.

Affected Software

VendorProductVersion RangeStatus
python-social-authsocial-core< 5.0.0affected

Weaknesses

  • CWE-287: CWE-287: Improper Authentication
  • CWE-347: CWE-347: Improper Verification of Cryptographic Signature

References