Junglewise Threat Intelligence

CVE-2025-46573: Auth0 passport-wsfed-saml2 authentication bypass via SAML attribute smuggling

CVE-2025-46573 · Severity: medium · CVSS 4 · Published 2025-05-06

Technologies: passport-wsfed-saml2 (npm). Vendors: npm, Auth0.

Executive brief

Passport-wsfed-saml2 is a Node.js library used to add SAML-based single sign-on (SSO) authentication to web applications. An attacker who obtains a valid SAML response from an identity provider can manipulate it by adding extra attributes, allowing them to impersonate any user and bypass authentication controls. This could lead to unauthorized access to sensitive user accounts and data.

Technical details

This vulnerability is a SAML authentication bypass resulting from improper attribute validation (CWE-287, CWE-290). The root cause is insufficient sanitization of SAML response attributes; an attacker can inject or modify attributes in a validly-signed SAML assertion to impersonate arbitrary users. The attack requires a valid SAML response signed by the identity provider, but no additional authentication or user interaction is needed once this response is obtained. An attacker can achieve full user impersonation and account takeover. The fix is available in version 4.6.4 and later.

Affected products

  • Auth0 passport-wsfed-saml2 3.0.5 to 4.6.3

Timeline

  • 2025-05-06: disclosed
  • 2025-05-06: patched: v4.6.4 and later

References

Related threats