vulns.co
/
GKData.io MCP

samlify · 1 min read

samlify: signing does not establish claim provenance

The maintainer describes inconsistent escaping between XML attribute and element-text contexts during SAML assertion generation. User-controlled profile values could change assertion structure before the identity provider signed it. The service provider subsequently accepted extra attributes as authenticated claims; privilege escalation depends on using those attributes for authorization.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial reasoning: signatures protect the generated representation, not the authority of each input used to construct it. Keep profile text separate from authorization-claim structure, use context-correct serialization before signing, and review which upstream actors may supply claims consumed as roles. A signature check alone cannot repair a compromised issuance boundary.

Before reading

  • SAML issuer/relying-party roles, XML contexts and claim-based authorization

Context and limits

  • The advisory identifies master/v2.10.2 as affected and 2.13.0 as patched; it does not establish a complete affected-version interval. Exposure requires user-controlled values reaching assertion generation and a relying party trusting the resulting attributes.
  • The published example supports added attributes being parsed; downstream privileged application actions are conditional consequences, not evidence of a breached deployment.
  • tngan published the advisory; RootUp is credited as reporter in both advisory and release notes. The 2.13.0 release explicitly references this advisory. Its displayed May 14 timestamp omits the year in retrieved text, so no full patch date is asserted. Resource edition remains null.

Sources and provenance

  1. SAML attribute-generation integrity advisory samlify · reviewed 2026-10-03
  2. Release v2.13.0 samlify · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software