A critical authentication bypass in Samlifyallows attackers to log in as administrators by inserting unsigned malicious assertions inside legitimate, signed SAML responses.
See also: O2 UK fixes user location leak bug

Samlify is a high-level authentication library that helps developers integrate SAML SSO and Single Log-Out (SLO) into Node.js. It is a popular tool for deploying or connecting to Identity Providers (IdPs) and Service Providers (SPs) via the SAML protocol.
The library is widely used by SaaS platforms, organizations implementing SSO for internal tools, developers integrating with corporate identity providers like Azure AD or Okta, and in federated identity scenarios. It is extremely popular, with over 200,000 weekly downloads on npm.
The vulnerability, which has been registered as CVE-2025-47949 , is a critical “ Signature Wrapping ” bug (CVSS v4.0 score: 9.9) and affects all versions of Samlify before 2.10.0 .
As EndorLabs explained in a related report, Samlify correctly verifies that the XML document providing a user's identity is signed. However, it continues to read fake assertions from part of the XML that is not signed.
See also: Mozilla Firefox: Vulnerabilities discovered at Pwn2Own Berlin are being fixed
Attackers in possession of a valid signed SAML response – either through interception or public metadata – can modify it to exploit the library's parsing flaw and authenticate as a different user. This is a complete SSO bypass, allowing unauthorized remote attackers to escalate privileges and log in as administrators.

The attacker does not need any user interaction or special permissions. The only requirement is access to a valid, signed XML blob, which makes exploitation relatively simple.
To address the risk, users are advised to upgrade to the newest version Samlify 2.10.0, which was released earlier this month.
It is worth noting that the latest available version on GitHub remains 2.9.1, however npm already hosts the secure version 2.10.0 (at the time of writing). There have been no reported cases of active exploitation of the CVE-2025-47949 vulnerability, however affected users are urged to take immediate action and secure their environments.
See also: RD Gateway UAF vulnerability allows RCE
Based on the above, the Samlify bug highlights a critical and common problem in the implementation of the SAML (Security Assertion Markup Language) protocol : the incorrect processing and verification of signed XML documents . Although part of the XML is signed and verified, malicious users can insert unsigned information into places that are not properly protected and thus bypass the authentication process .
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
