Impact
This vulnerability allows an attacker who possesses any validly signed SAML message to prepend an unsigned assertion to the message. The library processes signature verification and assertion extraction using separate XPath lookups without cross‑validation. As a result, the forged assertion is accepted as the authenticated identity while the original signature is validated against the original assertion, enabling the attacker to impersonate arbitrary users.
Affected Systems
The issue is present in the krakenjs passport-saml-encrypted package. All versions up to and including 0.1.13 are impacted.
Risk and Exploitability
The CVSS score of 9.1 classifies this condition as critical. Although an EPSS score is not available, the lack of a KE wild yet; however, the high intrinsic severity and the ability to bypass authentication give attackers a severe advantage when they can supply a signed SAML payload. The vulnerability is exploitable remotely through any system that accepts SAML responses processed by the affected library. Attackers with the ability to supply or manipulate SAML assertions can gain unauthorized access or elevate privileges.
OpenCVE Enrichment