© 2025-2026 PySpect
First version without a known vulnerability: 5.0.0
social-auth-core has a Session Fixation issue
Fixed in: 5.0.0
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
Fixed in: 5.0.0
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
Fixed in: 5.0.0
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
Fixed in: 5.0.0
social-auth-core has an Improper Authentication issue
Fixed in: 5.0.0