Executive brief
xml-crypto is a widely-used Node.js library for validating digitally signed XML documents, commonly used in SAML-based authentication systems. A vulnerability allows attackers to inject comments into XML digest values, causing signature verification to pass for tampered documents. This could enable account takeover, privilege escalation, or impersonation by modifying authentication tokens or access control attributes while maintaining valid signatures.
Technical details
The vulnerability is an improper cryptographic signature verification issue (CWE-347) affecting xml-crypto versions ≤6.0.0. The root cause is insufficient validation of the DigestValue element structure during XML signature verification; attackers can inject XML comments into DigestValue nodes, which are then included in the digest calculation, allowing a modified document to pass signature checks. The attack requires network access to supply a crafted XML payload to an application using xml-crypto, with no authentication or user interaction required. An attacker can modify signed XML messages (such as SAML responses) to alter identity or authorization attributes while preserving cryptographic validity. Patches are available in version 6.0.1 (main line), 3.2.1 (v3.x), and 2.1.6 (v2.x).
Affected products
- node-saml xml-crypto ≤6.0.0 (fixed in 6.0.1, 3.2.1, 2.1.6)
Timeline
- 2025-03-14: disclosed
- 2025-03-14: patched