Authentication Bypass by Spoofing Affecting social-auth-app-django package, versions [,5.6.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.19% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-SOCIALAUTHAPPDJANGO-13512562
  • published10 Oct 2025
  • disclosed9 Oct 2025
  • creditmel-mason, Ivan Studinsky

Introduced: 9 Oct 2025

NewCVE-2025-61783  (opens in a new tab)
CWE-290  (opens in a new tab)

How to fix?

Upgrade social-auth-app-django to version 5.6.0 or higher.

Overview

social-auth-app-django is a Python Social Authentication, Django integration.

Affected versions of this package are vulnerable to Authentication Bypass by Spoofing. An attacker can gain unauthorized access to user accounts by exploiting improper association by email when a third-party authentication service does not validate or enforce unique email addresses.

Workaround

This vulnerability can be mitigated by reviewing the authentication service policy on email addresses to ensure they require validation and uniqueness.

CVSS Base Scores

version 4.0
version 3.1