PT-2025-41492 · Unknown+1 · Python Social Auth+1

Mel-Mason

+1

·

Published

2025-10-09

·

Updated

2026-04-07

·

CVE-2025-61783

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Python Social Auth versions prior to 5.6.0
Description Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, a user could be associated by email during authentication even if the associate by email pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided email addresses or does not require unique email addresses.
Recommendations Update to version 5.6.0 or later. Review the authentication service policy on email addresses.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61783
GHSA-WV4W-6QV2-QQFG
OPENSUSE-SU-2026:10499-1

Affected Products

Debian
Python Social Auth