Description
Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.
Published: 2025-10-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wv4w-6qv2-qqfg Python Social Auth - Django has unsafe account association
History

Wed, 15 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Oct 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Fri, 10 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Python-social-auth
Python-social-auth social-app-django
Vendors & Products Python-social-auth
Python-social-auth social-app-django

Thu, 09 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Description Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.
Title Python Social Auth - Django has unsafe account association
Weaknesses CWE-303
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Python-social-auth Social-app-django
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-15T19:49:22.392Z

Reserved: 2025-09-30T19:43:49.902Z

Link: CVE-2025-61783

cve-icon Vulnrichment

Updated: 2025-10-15T19:48:58.459Z

cve-icon NVD

Status : Deferred

Published: 2025-10-09T21:15:40.127

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-61783

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-09T20:57:20Z

Links: CVE-2025-61783 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-10-10T11:17:32Z

Weaknesses