Email Association Vulnerability in Python Social Auth by Python
CVE-2025-61783
What is CVE-2025-61783?
Python Social Auth, a mechanism for social authentication and registration, contains a vulnerability in versions prior to 5.6.0. During the authentication process, users can be associated with accounts via email even if the associate_by_email pipeline is not included. This flaw may result in account compromise, particularly when third-party authentication services fail to validate email addresses or enforce unique emails. The issue is addressed in version 5.6.0, and users are advised to check their authentication service policies regarding email usage as a workaround.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
social-app-django < 5.6.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
