Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.
History

Thu, 09 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
Description Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.
Title Python Social Auth - Django has unsafe account association
Weaknesses CWE-303
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-09T20:57:20.734Z

Reserved: 2025-09-30T19:43:49.902Z

Link: CVE-2025-61783

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-09T21:15:40.127

Modified: 2025-10-09T21:15:40.127

Link: CVE-2025-61783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.