Executive brief
Casdoor, an identity and access management platform, contains a flaw in how it handles login requests from external identity providers. The system fails to verify that an incoming login response actually matches a request it previously sent, allowing attackers to submit unsolicited or old login data. If exploited, an attacker could gain persistent, unauthorized access to user accounts, including administrative accounts, potentially leading to a full system compromise.
Technical details
A vulnerability exists in the SAML callback handler within `controllers/auth.go` of Casdoor. The `/api/acs` endpoint accepts any well-formed `SAMLResponse` without verifying its correlation to a previously issued `AuthnRequest`. Furthermore, the handler uses a provider snapshot loaded at the start of a request, meaning it may process responses for Identity Providers (IdPs) that were disabled or deleted mid-flow. An attacker controlling a registered upstream IdP can exploit this to send unsolicited responses or replay captured responses to obtain authenticated sessions. As of the advisory date, no patch is available.
Affected products
- Casdoor Casdoor <= 2.362.0
Timeline
- 2026-05-28: advisory: Initial disclosure by CERT/CC and GitHub Advisory Database
- 2026-05-28: disclosed