Executive brief
passport-saml-encrypted is a Node.js authentication plugin that handles SAML single sign-on (SSO) for web applications. The vulnerability allows attackers to bypass authentication entirely by submitting forged SAML responses without valid signatures, potentially gaining unauthorized access to user accounts and sensitive data without knowing valid credentials.
Technical details
The vulnerability exists in passport-saml-encrypted through version 0.1.13, where SAML signature verification is made conditional on an optional cert configuration parameter. An attacker can craft unsigned or maliciously signed SAML responses and submit them directly to the application's assertion consumer service (ACS) endpoint. When no certificate is configured, the library skips signature validation entirely, allowing the attacker to inject arbitrary NameID and attribute claims. This results in complete authentication bypass without requiring any valid SAML signature. The attack is network-reachable and requires no user interaction or prior authentication.
Affected products
- Kraken passport-saml-encrypted through 0.1.13
Timeline
- 2026-09-10: disclosed