CVE-2025-14546: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-14546 is a Cross-Site Request Forgery (CSRF) vulnerability in the fastapi-sso Python package affecting all versions before 0.19.0. The flaw stems from improper validation of the OAuth state parameter during the authentication callback, enabling a remote attacker to trick a victim into visiting a malicious callback URL and linking the attacker's account to the victim's internal account — a "1-click account takeover" scenario. The vulnerability was discovered by David Borș of Snyk Security Research, disclosed on December 9, 2025, and published on December 19, 2025. It carries a CVSS v3.1 base score of 6.3 (Medium) and a CVSS v4.0 score of 5.4 (Medium) per NVD (Github Advisory, Snyk).

Technical details

The root cause is classified as CWE-285 (Improper Authorization) and CWE-352 (Cross-Site Request Forgery). The get_login_url method in fastapi_sso/sso/base.py generates an OAuth state value but never persists it server-side or binds it to the user's session. During the callback, verify_and_process blindly copies the attacker-supplied state query parameter into self._state without comparing it against any trusted stored value, violating RFC 6749 Section 10.12. The fix (commit 6117d1a) addresses this by storing the state in a sso_state cookie during login redirect and validating it against the callback's state parameter before processing (GitHub Commit, GitHub Issue, Snyk).

Impact

Successful exploitation allows an attacker to permanently link their own SSO identity to a victim's existing application account, effectively achieving account takeover. The primary impact is high confidentiality loss — the attacker gains access to the victim's account and all associated data — with a low integrity impact from the unauthorized account association. Availability is not affected. The scope of impact depends on the application's account-linking logic, but in the worst case, the attacker gains full persistent access to the victim's account without the victim's knowledge (Snyk, GitHub Issue).

Exploitability

Snyk has documented a proof-of-concept (PoC) for this vulnerability, and the CVSS v4.0 exploit maturity is rated "Proof of Concept." There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.1% (27th percentile), indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Snyk, Github Advisory).

Exploitation steps

  1. Setup: The attacker creates or already has an account with the OAuth provider (e.g., Google, Microsoft) used by the target FastAPI SSO application.
  2. Initiate OAuth flow: The attacker begins a legitimate SSO login flow against the target application, obtaining a valid authorization code and state from the OAuth provider — but stops before submitting the callback to the application.
  3. Craft malicious callback URL: The attacker constructs a callback URL to the target application's OAuth callback endpoint (e.g., /auth/callback?code=ATTACKER_CODE&state=ATTACKER_STATE) using their own code and state values.
  4. Social engineering: The attacker tricks a logged-in victim into visiting the crafted callback URL via phishing, a drive-by attack, or an embedded link. The victim must already be authenticated to the target application.
  5. Exploit missing state validation: Because verify_and_process accepts the attacker-supplied state without checking it against a session-bound value, the callback is processed successfully. The attacker's grant code is exchanged with the OAuth provider.
  6. Account linking: The application's account-linking logic associates the attacker's SSO identity with the victim's existing internal account, granting the attacker persistent access to the victim's account (Snyk, GitHub Issue).

Indicators of compromise

  • Logs: Unexpected OAuth callback requests (e.g., GET /auth/callback) from IP addresses or user agents inconsistent with the victim's normal session; callback requests where the state parameter does not match any recently initiated login flow.
  • Application Behavior: Sudden appearance of a new SSO identity linked to an existing user account without the user initiating a re-authentication or account-linking action; user reports of unexpected account access or unfamiliar linked identities in account settings.
  • Network: OAuth callback requests originating from unusual referrers or with no referrer header, suggesting the URL was visited directly rather than as part of a normal OAuth redirect flow.

Mitigation and workarounds

Upgrade fastapi-sso to version 0.19.0 or later, which enforces state validation by storing the state in a sso_state cookie during the login redirect and verifying it against the callback's state parameter before processing. There is no documented configuration-based workaround for older versions; upgrading is the only reliable fix. As an additional defense-in-depth measure, application developers should implement their own session-bound state validation and avoid using non-random, predictable state values as previously suggested in the library's documentation (Github Advisory, GitHub Commit).

Community reactions

The vulnerability was reported by David Borș of Snyk Security Research and disclosed responsibly to the maintainer on December 9, 2025, with a fix released on December 19, 2025. The GitHub issue was labeled as a security concern by the repository maintainer. Snyk published a detailed advisory and PoC description, and the issue received coverage from several vulnerability tracking platforms. No significant broader media coverage or notable community controversy has been identified (Snyk, GitHub Issue).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management