Junglewise Threat Intelligence

CVE-2025-47949: samlify SAML Signature Wrapping attack

CVE-2025-47949 · Severity: medium · CVSS 4 · Published 2025-05-19

Technologies: samlify (npm). Vendors: npm.

Executive brief

samlify is a Node.js library that handles SAML authentication, a common protocol for enterprise single sign-on. A signature wrapping attack in samlify allows attackers to forge SAML authentication responses and impersonate any user, provided they have access to a legitimate signed XML document from an identity provider. This could allow unauthorized access to applications relying on samlify for authentication.

Technical details

A Signature Wrapping attack (CWE-347) has been identified in samlify versions prior to 2.10.0. The vulnerability allows an attacker to manipulate SAML response messages by wrapping signed XML elements in such a way that the signature validation logic is bypassed or misinterpreted. An attacker with access to a legitimately signed XML document from an identity provider can craft a forged SAML Response that authenticates as any user. The attack is network-reachable and requires no authentication or user interaction. The vulnerability has been patched in version 2.10.0 and later.

Affected products

  • samlify samlify < 2.10.0

Timeline

  • 2025-05-19: disclosed
  • 2025-05-19: patched: patched in version 2.10.0

References

Related threats