๐Ÿ” CVE Alert

CVE-2026-57175

MEDIUM 6.4

social-auth-core has an Improper Authentication issue

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs.

CWE CWE-287
Vendor python-social-auth
Product social-core
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for python-social-auth social-core

Be the first to know when new medium vulnerabilities affecting python-social-auth social-core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

python-social-auth / social-core
< 5.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j