CVE-2026-89043: passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending

Published Sep 10, 2026
·
Updated

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion.

Affected Software

1 affected component
passport-saml-encrypted<=0.1.13

Event History

Sep 10, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker needs any validly signed SAML message. They can prepend a forged, unsigned assertion so that signature validation succeeds for the original assertion while identity extraction uses the forged assertion.

2

Which deployments are affected?

Deployments using passport-saml-encrypted version 0.1.13 or earlier are affected. The supplied data does not identify any configuration prerequisite or mitigation through configuration changes.

3

What is the likely impact if exploitation succeeds?

An attacker may be accepted as the identity specified in the forged assertion. The vulnerability is rated high and has high confidentiality and integrity impact in the provided vector.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203