GHSA-4mxg-3p6v-xgq3
CRITICALCVE-2025-54419Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature.
- Affected
- <= 5.0.1
- Fixed in
- 5.1.0
- Weakness
- CWE-287
- Published
- 2025-07-28
- Source
- github