CVE-2025-54369
Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML assertion. For example, in one attack it is possible to remove any character from the SAML assertion username. This issue is fixed in version 5.1.0.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.55%
- CWE
- CWE-87, CWE-347
- Published
- 2025-12-12
- Last modified
- 2026-05-07
Affected products
- node-saml node-saml
Weakness type
Related vulnerabilities
- CVE-2026-79946 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-54002 — Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
- CVE-2026-55661 — TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
- CVE-2026-55237 — AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
- CVE-2026-46492 — md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
- CVE-2026-25688 — Apache Answer: XSS in AI Answer Rendering
- CVE-2026-45314 — Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
- CVE-2026-42458 — Magento LTS: Reflected XSS - Import -> Data Flow (profiles)