GHSA-m837-g268-mmv7
CRITICALCVE-2025-54369Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature.
- Affected
- <= 3.1.2
- Fixed in
- not stated
- Weakness
- CWE-87
- Published
- 2025-07-25
- Source
- github