Critical Samlify SSO flaw lets attackers log in as admin

By inserting unsigned harmful assertions within validly signed SAML responses, a serious vulnerability in Samlify authentication bypass has been found that enables attackers to pose as admin users.

A high-level authentication library called Samlify assists programmers in incorporating Single Log-Out (SLO) and SAML SSO into Node.js applications. It is a widely used tool for establishing or establishing connections with service providers (SPs) and identity providers (IdPs) via SAML.

The library is used in federated identity management scenarios, by SaaS platforms, by companies installing SSO for internal tools, and by developers interfacing with corporate identity providers such as Okta or Azure AD. It has received over 200,000 downloads each week on npm, indicating its high level of popularity.

The vulnerability, identified as CVE-2025-47949, affects all Samlify versions prior to 2.10.0 and is a critical (CVSS v4.0 score: 9.9) Signature Wrapping problem.

According to a report from EndorLabs, Samlify accurately confirms that the XML document containing a user’s identification is signed read more about Critical Samlify SSO flaw lets attackers log in as admin.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *