{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/social-auth-core--5.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:python_social_auth:social_auth_core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-57178"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["social-auth-core (\u003c 5.0.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","web-vulnerability","python-social-auth"],"_cs_type":"advisory","_cs_vendors":["python-social-auth"],"content_html":"\u003cp\u003eA vulnerability (CVE-2026-57178) exists in the social-auth-core library affecting the \u003ccode\u003evk-app\u003c/code\u003e backend. When an application processes callback data from the VK platform, the library fails to enforce signature verification if the \u003ccode\u003eauth_key\u003c/code\u003e parameter is omitted from the request. This flaw allows an attacker to manipulate callback parameters such as \u003ccode\u003eviewer_id\u003c/code\u003e, \u003ccode\u003eaccess_token\u003c/code\u003e, \u003ccode\u003eapi_id\u003c/code\u003e, and \u003ccode\u003eapi_result\u003c/code\u003e. By crafting a malicious request without an \u003ccode\u003eauth_key\u003c/code\u003e, an attacker can inject arbitrary identity information, tricking the backend into authenticating them as any VK user. This vulnerability is specific to the \u003ccode\u003esocial_core.backends.vk.VKAppOAuth2\u003c/code\u003e implementation. Defending against this requires upgrading to version 5.0.0 or later, or disabling the affected authentication backend entirely.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full authentication bypass and identity impersonation within any web application that relies on the \u003ccode\u003evk-app\u003c/code\u003e backend for user login. An attacker can gain unauthorized access to victim accounts, access user-specific data, and perform actions on behalf of legitimate users. The vulnerability affects all users of social-auth-core versions prior to 5.0.0 utilizing the VK App OAuth2 backend.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade social-auth-core to version 5.0.0 or later to ensure the \u003ccode\u003eauth_key\u003c/code\u003e parameter is strictly required for signature verification.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, disable the vulnerable backend by removing \u003ccode\u003esocial_core.backends.vk.VKAppOAuth2\u003c/code\u003e from the \u003ccode\u003eSOCIAL_AUTH_AUTHENTICATION_BACKENDS\u003c/code\u003e configuration in your application settings.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:04:32Z","date_published":"2026-09-24T20:04:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-social-auth-core-auth-bypass/","summary":"The social-auth-core library fails to verify signatures in the vk-app backend when the auth_key parameter is missing, allowing attackers to impersonate arbitrary VK users.","title":"Authentication Bypass in social-auth-core VK App Backend","url":"https://feed.craftedsignal.io/briefs/2026-09-social-auth-core-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Social-Auth-Core (\u003c 5.0.0)","version":"https://jsonfeed.org/version/1.1"}