Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-34r5-q4jw-r36m | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 09 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samlify Project
Samlify Project samlify |
|
| CPEs | cpe:2.3:a:samlify_project:samlify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Samlify Project
Samlify Project samlify |
|
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tngan
Tngan samlify |
|
| Vendors & Products |
Tngan
Tngan samlify |
Mon, 08 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new <saml:Attribute> elements inside the signed assertion. The IdP then signs the tampered assertion and the SP accepts the injected attributes as trusted. This allows privilege escalation when attributes are used for authorization (roles/groups). This issue has been patched in version 2.13.0. | |
| Title | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions | |
| Weaknesses | CWE-91 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T15:13:53.540Z
Reserved: 2026-05-14T18:06:06.811Z
Link: CVE-2026-46490
Updated: 2026-06-09T14:51:10.801Z
Status : Analyzed
Published: 2026-06-08T19:16:45.950
Modified: 2026-06-09T16:48:56.767
Link: CVE-2026-46490
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:56:36Z
Github GHSA