passport-saml-encrypted through 0.1.13 makes SAML...
Critical severity
Unreviewed
Published
Sep 10, 2026
to the GitHub Advisory Database
•
Updated Sep 10, 2026
Description
Published by the National Vulnerability Database
Sep 10, 2026
Published to the GitHub Advisory Database
Sep 10, 2026
Last updated
Sep 10, 2026
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
References