{"id":"UBUNTU-CVE-2025-61783","details":"Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses. Version 5.6.0 contains a patch. As a workaround, review the authentication service policy on e-mail addresses; many will not allow exploiting this vulnerability.","modified":"2026-05-20T16:23:39.187477044Z","published":"2025-10-09T21:15:00Z","upstream":["CVE-2025-61783"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-61783"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-61783"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/security/advisories/GHSA-wv4w-6qv2-qqfg"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/issues/220"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/issues/231"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/issues/634"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/pull/803"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/commit/10c80e2ebabeccd4e9c84ad0e16e1db74148ed4c"},{"type":"REPORT","url":"https://github.com/python-social-auth/social-app-django/commit/10c80e2ebabeccd4e9c84ad0e16e1db74148ed4c"}],"affected":[{"package":{"name":"social-auth-app-django","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/social-auth-app-django?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.0-2"],"ecosystem_specific":{"binaries":[{"binary_version":"3.1.0-2","binary_name":"python3-social-django"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61783.json"}},{"package":{"name":"social-auth-app-django","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/social-auth-app-django?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.0-2.1","5.0.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"5.0.0-1","binary_name":"python3-social-django"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61783.json"}},{"package":{"name":"social-auth-app-django","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/social-auth-app-django?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.2.0-2","5.4.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-social-django","binary_version":"5.4.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61783.json"}},{"package":{"name":"social-auth-app-django","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/social-auth-app-django?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.4.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-social-django","binary_version":"5.4.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61783.json"}},{"package":{"name":"social-auth-app-django","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/social-auth-app-django?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.4.3-1","5.4.3-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"5.4.3-1build1","binary_name":"python3-social-django"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-61783.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"},{"type":"Ubuntu","score":"medium"}]}