Geek-Guy.com

Category: Identity and Access Management, Security, Vulnerabilities

Samlify bug lets attackers bypass single sign-on

A critical vulnerability in the popular samlify library could potentially allow attackers to bypass Single Sign-On (SSO) protections and gain unauthorized access to systems relying on SAML for authentication. Tracked as CVE-2025-47949, the flaw affecting the widely used Node.js library can allow a Signature Wrapping attack with maximum impact, for which it received a critical…