๐Ÿ” CVE Alert

CVE-2025-54369

UNKNOWN 0.0

Node-SAML SAML Authentication Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
15th

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML assertion. For example, in one attack it is possible to remove any character from the SAML assertion username. This issue is fixed in version 5.1.0.

CWE CWE-87 CWE-347
Vendor node-saml
Product node-saml
Published Dec 12, 2025
Last Updated May 7, 2026
Stay Ahead of the Next One

Get instant alerts for node-saml node-saml

Be the first to know when new unknown vulnerabilities affecting node-saml node-saml are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

node-saml / node-saml
< 5.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/node-saml/node-saml/security/advisories/GHSA-m837-g268-mmv7 github.com: https://github.com/node-saml/node-saml/commit/31ead9411ebc3e2385086fa9149b6c17732bca10 github.com: https://github.com/node-saml/node-saml/releases/tag/v5.1.0