
🔴 social-auth-core, Authentication Bypass, #CVE-2026-57178 (High) -DC-Sep2026-2577 https://dailycve.com/social-auth-core-authentication-bypass-cve-2026-57178-high-dc-sep2026-2577/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 social-auth-core, Authentication Bypass, #CVE-2026-57178 (High) -DC-Sep2026-2577 https://dailycve.com/social-auth-core-authentication-bypass-cve-2026-57178-high-dc-sep2026-2577/