Vulnerability GHSA-vqg6-3fw6-j9jg

Medium Risk
MEDIUM RISK
CVSS Score: 4.2
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 days ago
September 24, 2026 at 07:58 PM UTC
social-auth-core has a Session Fixation issue
0.0.1 - 4.9.1
0.0.1 - 4.9.1

Summary

social-auth-core has a Session Fixation issue

Details

Impact

The partial-pipeline resume mechanism accepted partial_token as a bearer credential without binding it to the browser session that created it.

Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account.

The issue affects applications using partial pipeline steps such as mail_validation or custom steps decorated with @partial.

Patches

The issue has been fixed by binding partial pipeline resumes to the originating browser session.

Users should upgrade to a patched version.

Fix:

Workarounds

Applications that cannot upgrade immediately should disable resumable partial pipeline steps, including mail_validation and custom steps decorated with @partial.

If those flows are required, applications should avoid accepting partial resume links from untrusted contexts until a patched version can be deployed.

There is no complete workaround while continuing to use the vulnerable partial-pipeline resume mechanism.

Credits

Reported through GitHub private vulnerability reporting by Liyi Zhou, Ziyue Wang, Strick, Maurice, and Chenchen Yu from the University of Sydney security research team.

Reporter references:

Impacted packages

Timeline

Published
3 days ago
September 24, 2026 at 07:58 PM UTC
Fixed (5.0.0)
3 months ago
June 23, 2026 at 02:18 PM UTC
Last Modified
3 days ago
September 24, 2026 at 08:15 PM UTC