samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
41Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 8.7epss 0.5%
da publicação à arma22 dias
Publicada no NVD8 de jun.
1ª PoC+22d
probabilidade de exploração
0.5%top 62% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new <saml:Attribute> elements inside the signed assertion. The IdP then signs the tampered assertion and the SP accepts the injected attributes as trusted. This allows privilege escalation when attributes are used for authorization (roles/groups). This issue has been patched in version 2.13.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
tngan · samlifyPoCs públicas encontradas — 1
githubgithub.com/BiiTts/CVE-2026-46490-samlify-SAML-Attribute-Injection★ 0⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.