High severity7.4NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026
CVE-2026-89043
CVE-2026-89043
Description
passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=0.1.13+ 1 more
- (no CPE)range: <=0.1.13
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.jsnvd
- github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.jsnvd
- github.com/krakenjs/passport-saml-encrypted/issues/30nvd
- www.vulncheck.com/advisories/passport-saml-encrypted-through-0.1.13-xml-signature-wrapping-via-assertion-prependingnvd
News mentions
0No linked articles in our index yet.