CVE-2025-54369 - CVE House
Back to Database
Status published Critical CVE-2025-54369

Node-SAML SAML Authentication Bypass

Vulnerability Description

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML assertion. For example, in one attack it is possible to remove any character from the SAML assertion username. This issue is fixed in version 5.1.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54369

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

node-saml
Vulnerable Versions:
< 5.1.0

Timeline

Official Publish: December 12th, 2025
Last Modified: May 7th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)