Authentication Flaw in LoginRadius Backend of Python Social Auth
CVE-2026-57177

4.3MEDIUM

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-57177?

The LoginRadius backend within Python Social Auth is vulnerable to a Cross-Site Request Forgery (CSRF) attack due to a lack of validation of the OAuth state during the authentication process. This vulnerability allows an attacker to exploit the victim's browser session and authenticate as the attacker by using a malicious LoginRadius token. This flaw specifically affects applications that utilize the LoginRadius backend for authentication. The issue has been addressed in version 5.0.0, which introduced callback state validation to mitigate this security risk.

Affected Version(s)

social-core < 5.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.