HomeSecuritySamlify SSO bug allows login as administrator

Samlify SSO error allows login as administrator

A critical authentication bypass in Samlifyallows attackers to log in as administrators by inserting unsigned malicious assertions inside legitimate, signed SAML responses.

See also: O2 UK fixes user location leak bug

Samlify error

Samlify is a high-level authentication library that helps developers integrate SAML SSO and Single Log-Out (SLO) into Node.js. It is a popular tool for deploying or connecting to Identity Providers (IdPs) and Service Providers (SPs) via the SAML protocol.

The library is widely used by SaaS platforms, organizations implementing SSO for internal tools, developers integrating with corporate identity providers like Azure AD or Okta, and in federated identity scenarios. It is extremely popular, with over 200,000 weekly downloads on npm.

The vulnerability, which has been registered as CVE-2025-47949 , is a critical “ Signature Wrapping ” bug (CVSS v4.0 score: 9.9) and affects all versions of Samlify before 2.10.0 .

As EndorLabs explained in a related report, Samlify correctly verifies that the XML document providing a user's identity is signed. However, it continues to read fake assertions from part of the XML that is not signed.

See also: Mozilla Firefox: Vulnerabilities discovered at Pwn2Own Berlin are being fixed

Attackers in possession of a valid signed SAML response – either through interception or public metadata – can modify it to exploit the library's parsing flaw and authenticate as a different user. This is a complete SSO bypass, allowing unauthorized remote attackers to escalate privileges and log in as administrators.

Samlify SSO error allows login as administrator
Samlify SSO error allows login as administrator

The attacker does not need any user interaction or special permissions. The only requirement is access to a valid, signed XML blob, which makes exploitation relatively simple.

To address the risk, users are advised to upgrade to the newest version Samlify 2.10.0, which was released earlier this month.

It is worth noting that the latest available version on GitHub remains 2.9.1, however npm already hosts the secure version 2.10.0 (at the time of writing). There have been no reported cases of active exploitation of the CVE-2025-47949 vulnerability, however affected users are urged to take immediate action and secure their environments.

See also: RD Gateway UAF vulnerability allows RCE

Based on the above, the Samlify bug highlights a critical and common problem in the implementation of the SAML (Security Assertion Markup Language) protocol : the incorrect processing and verification of signed XML documents . Although part of the XML is signed and verified, malicious users can insert unsigned information into places that are not properly protected and thus bypass the authentication process .

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS