Home / Companies / Stytch / Blog / Post Details
Content Deep Dive

Authentication bypass vulnerabilities in node-saml

Blog post from Stytch

Post Details
Company
Date Published
Author
Stytch Team
Word Count
1,218
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

In March 2025, the Stytch team identified and addressed authentication bypass vulnerabilities in the node-saml library, stemming from improper validation in the xml-crypto library used for verifying signatures in SAML assertions. These vulnerabilities allowed for a signature wrap attack and the exploitation of multiple SignedInfo nodes, which could enable unauthorized login as any user. Stytch ensured their customers were unaffected and implemented solutions to strip comments from XML and block multiple SignedInfo nodes to prevent such attacks. They confirmed, with the help of a third party, that their systems had not been exploited, and introduced additional monitoring and security measures. Stytch has released a patched version of xml-crypto and extended gratitude to the researcher who disclosed the vulnerabilities.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Platform Engineering 1 224 64 33 +9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.