PT-2025-41492 · Unknown+1 · Python Social Auth+1
Mel-Mason
+1
·
Published
2025-10-09
·
Updated
2026-04-07
·
CVE-2025-61783
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Python Social Auth versions prior to 5.6.0
Description
Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, a user could be associated by email during authentication even if the
associate by email pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided email addresses or does not require unique email addresses.Recommendations
Update to version 5.6.0 or later.
Review the authentication service policy on email addresses.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Python Social Auth