Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15809 | samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider. Version 2.10.0 fixes the issue. |
Github GHSA |
GHSA-r683-v43c-6xqv | samlify SAML Signature Wrapping attack |
Fri, 19 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samlify Project
Samlify Project samlify |
|
| CPEs | cpe:2.3:a:samlify_project:samlify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Samlify Project
Samlify Project samlify |
|
| Metrics |
cvssV3_1
|
Tue, 20 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 May 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider. Version 2.10.0 fixes the issue. | |
| Title | samlify SAML Signature Wrapping attack | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-20T13:00:40.340Z
Reserved: 2025-05-14T10:32:43.530Z
Link: CVE-2025-47949
Updated: 2025-05-20T13:00:37.335Z
Status : Analyzed
Published: 2025-05-19T20:15:26.287
Modified: 2025-09-19T17:32:34.830
Link: CVE-2025-47949
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA