216.73.217.22

CVE-2026-46490

· Published 08/06/2026 19:16 · Modified 09/06/2026 16:48

Labels: CVE-2026-46490 2026-06-08CVE-2026-46490CWE-91[email protected]

Essential information

Published
08/06/2026 19:16
Modified
09/06/2026 16:48
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new <saml:Attribute> elements inside the signed assertion. The IdP then signs the tampered assertion and the SP accepts the injected attributes as trusted. This allows privilege escalation when attributes are used for authorization (roles/groups). This issue has been patched in version 2.13.0.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
samlify project / samlify cpe:2.3:a:samlify_project:samlify:*:*:*:*:*:*:*:*

References