This vulnerability allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be done by using a valid SAML object that was signed by the configured IdP.
You are affected by this SAML Signature Wrapping vulnerability if you are using passport-wsfed-saml2 version 4.6.3 or below, specifically under the following conditions:
passport-wsfed-saml2,Upgrade to v4.6.4 or greater.
{
"cwe_ids": [
"CWE-287",
"CWE-347"
],
"github_reviewed": true,
"github_reviewed_at": "2025-05-06T21:18:43Z",
"nvd_published_at": "2025-05-06T21:16:20Z",
"severity": "CRITICAL"
}