CVE-2026-57177
4.3 MEDIUMpublic exploit availablePublished 2026-09-24 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weaknesses
CWE-352
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-15399
- MEDIUMCVE-2026-100524PoC
- MEDIUMCVE-2026-100712PoC
- UNSCOREDCVE-2026-100747
- UNSCOREDCVE-2026-100748
- UNSCOREDCVE-2026-100749
- MEDIUMCVE-2026-100873PoC
- MEDIUMCVE-2026-101093PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.