HIGHnpm
GHSA-34r5-q4jw-r36m· CVE-2026-46490samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
Modified: 6/9/2026
package
pkg:npm/samlify
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
Modified: 6/9/2026
Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames
Modified: 11/8/2023
samlify SAML Signature Wrapping attack
Modified: 5/19/2025