Executive brief
passport-saml-encrypted is a Node.js library that handles SAML authentication for web applications. The library contains a critical flaw in how it validates SAML assertions: it checks the digital signature and extracts the user identity in two separate, independent steps without verifying they match. An attacker with any validly signed SAML message can forge a fake identity assertion and prepend it to the signed one, causing the library to accept the forged identity while the legitimate signature passes validation against the original assertion, enabling complete authentication bypass.
Technical details
The vulnerability is an XML signature wrapping flaw in the SAML assertion validation logic. The affected library uses independent XPath lookups to verify the XML signature and extract the assertion content, with no cross-validation between the two operations. An attacker possessing any validly signed SAML response can craft a malicious assertion and prepend it to the legitimate one. The verification step passes because it validates the original signature, while the extraction step returns the attacker-controlled forged assertion. This allows authentication bypass for any user who can trigger a SAML authentication flow. No patches are currently referenced in the advisory.
Affected products
- KrakenJS passport-saml-encrypted through 0.1.13
Timeline
- 2026-09-10: disclosed