CVE-2025-46572

CRITICAL

passport-wsfed-saml2 <4.6.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be done by using a valid SAML object that was signed by the configured IdP. Users are affected specifically when the service provider is using passport-wsfed-saml2 and a valid SAML document signed by the Identity Provider can be obtained. Version 4.6.4 contains a fix for the vulnerability.

Scores

CVSS v4 9.3
EPSS 0.0030
EPSS Percentile 53.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
auth0/passport-wsfed-saml2 >= 3.0.5, < 4.6.4
npm/passport-wsfed-saml2 3.0.5 - 4.6.4npm
Published May 06, 2025
Tracked Since Feb 18, 2026