Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

CVE-2025-47949 Reveals Flaw in samlify That Opens Door to SAML Single Sign-On Bypass

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Meenakshi S L
Word Count
861
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

A critical vulnerability, identified as CVE-2025-47949, has been discovered in samlify, a popular Node.js library used for implementing SAML 2.0 Single Sign-On (SSO), affecting versions prior to 2.10.0. This vulnerability, a Signature Wrapping attack, allows attackers to forge SAML Responses, potentially leading to authentication bypass and user impersonation, including administrative accounts, by exploiting a parsing flaw in the Service Provider's SAML library. It is considered easy to exploit, requiring only a legitimately signed XML document from an Identity Provider. To mitigate this risk, users are urged to immediately upgrade to samlify version 2.10.0 or later. Samlify's widespread use, with over 200,000 weekly npm downloads, amplifies the potential impact of this security flaw, emphasizing the importance of prompt action to secure systems relying on this library.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.