Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-34r5-q4jw-r36m | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions |
Tue, 09 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samlify Project
Samlify Project samlify |
|
| CPEs | cpe:2.3:a:samlify_project:samlify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Samlify Project
Samlify Project samlify |
|
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tngan
Tngan samlify |
|
| Vendors & Products |
Tngan
Tngan samlify |
Mon, 08 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new <saml:Attribute> elements inside the signed assertion. The IdP then signs the tampered assertion and the SP accepts the injected attributes as trusted. This allows privilege escalation when attributes are used for authorization (roles/groups). This issue has been patched in version 2.13.0. | |
| Title | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions | |
| Weaknesses | CWE-91 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T15:13:53.540Z
Reserved: 2026-05-14T18:06:06.811Z
Link: CVE-2026-46490
Updated: 2026-06-09T14:51:10.801Z
Status : Analyzed
Published: 2026-06-08T19:16:45.950
Modified: 2026-06-09T16:48:56.767
Link: CVE-2026-46490
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:56:36Z
Github GHSA