FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

py-social-auth-app-django -- Unsafe account association

Affected packages
py310-social-auth-app-django < 5.4.3_1
py311-social-auth-app-django < 5.4.3_1
py312-social-auth-app-django < 5.4.3_1
py39-social-auth-app-django < 5.4.3_1
py310-dj51-social-auth-app-django < 5.6.0
py311-dj51-social-auth-app-django < 5.6.0
py312-dj51-social-auth-app-django < 5.6.0
py310-dj52-social-auth-app-django < 5.6.0
py311-dj52-social-auth-app-django < 5.6.0
py312-dj52-social-auth-app-django < 5.6.0

Details

VuXML ID 3116b6f3-b433-11f0-82ac-901b0edee044
Discovery 2025-10-09
Entry 2025-10-29

Michal Čihař reports:

Upon authentication, the user could be associated by e-mail even if the associate_by_email pipeline was not included. This could lead to account compromise when a third-party authentication service does not validate provided e-mail addresses or doesn't require unique e-mail addresses.

References

CVE Name CVE-2025-61783
URL https://nvd.nist.gov/vuln/detail/CVE-2025-61783