Skip to content
Critical XML Signature Wrapping Vulnerability in passport-saml-encrypted

Critical XML Signature Wrapping Vulnerability in passport-saml-encrypted

First seen 11 Sep 2026, 00:45 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 22:47 UTC
  • CVE-2026-89043 affects passport-saml-encrypted version 0.1.13.
  • Attackers can exploit this flaw to impersonate identities without the signing key.
  • Immediate upgrade to a fixed version is necessary to mitigate risks.

The passport-saml-encrypted library version 0.1.13 contains a critical XML signature wrapping vulnerability, identified as CVE-2026-89043, allowing attackers to prepend forged unsigned assertions to validly signed SAML messages. This flaw enables identity impersonation, potentially leading to account takeovers and unauthorized access to sensitive applications. The vulnerability arises from independent XPath lookups for signature verification and assertion extraction, which lack cross-validation. Organizations using this library, particularly in internet-facing Node.js applications, are at high risk. Public proof-of-concept evidence has been released, increasing concerns about potential exploitation, although active exploitation has not yet been confirmed. Immediate action is recommended to mitigate risks associated with this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-04-17
CVE-2017-11429 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-10
CVE-2026-89043 published
CVE-2026-89043 was officially published, highlighting the XML signature wrapping vulnerability in passport-saml-encrypted.
Redpacketsecurity
2026-09-11
Vulnerability confirmed in testing
Testing confirmed the vulnerability in a local environment using a real RSA keypair and XML-DSig signature.
github.com
2026-09-11
Public proof-of-concept released
Public proof-of-concept evidence for exploiting the vulnerability has been made available, raising exploitation concerns.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2017-11429 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed