GHSA-2xp3-57p7-qf4v is a critical-severity (CVSS 10) CWE-347 vulnerability in xml-crypto. A fix is available for xml-crypto — see the affected versions and patch details below.
xml-crypto vulnerable to XML signature verification bypass due improper verification of signature/signature spoofing
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- A successful exploit gives an attacker total control of the affected component, not partial access.
Exploitation and automatability from CISA’s SSVC triage for GHSA-2xp3-57p7-qf4v.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-2xp3-57p7-qf4v by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 379,842 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
xml-cryptonpmDescription
Summary
Default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of https://www.w3.org/TR/2008/REC-xmldsig-core-20080610/#sec-CoreValidation. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a <KeyInfo /> element, and pass xml-crypto default validation checks.
Details
Affected xml-crypto versions between versions >= 4.0.0 and < 6.0.0.
xml-crypto trusts by default any certificate provided via digitally signed XML document's <KeyInfo />.
xml-crypto prefers to use any certificate provided via digitally signed XML document's <KeyInfo /> even if library was configured to use specific certificate (publicCert) for signature verification purposes.
Attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to <KeyInfo /> element.
Vulnerability is combination of changes introduced to 4.0.0 at
- https://github.com/node-saml/xml-crypto/pull/301
- https://github.com/node-saml/xml-crypto/commit/c2b83f984049edb68ad1d7c6ad0739ec92af11ca
Changes at PR provided default method to extract certificate from signed XML document.
- https://github.com/node-saml/xml-crypto/blob/c2b83f984049edb68ad1d7c6ad0739ec92af11ca/lib/signed-xml.js#L405-L414
- https://github.com/node-saml/xml-crypto/blob/c2b83f984049edb68ad1d7c6ad0739ec92af11ca/lib/signed-xml.js#L334
and changes at PR prefer output of that method to be used as certificate for signature verification even in the case when library is configured to use specific/pre-configured signingCert
Name of the signingCert was changed later (but prior to 4.0.0 release) to publicCert:
- https://github.com/node-saml/xml-crypto/commit/78329fbae34c9b25ba25882604e960f506d7c0e7
- https://github.com/node-saml/xml-crypto/blob/78329fbae34c9b25ba25882604e960f506d7c0e7/lib/signed-xml.js#L507
Issue was fixed to 6.0.0 by disabling implicit usage of default getCertFromKeyInfo implementation:
- https://github.com/node-saml/xml-crypto/pull/445
- https://github.com/node-saml/xml-crypto/commit/21201723d2ca9bc11288f62cf72552b7d659b000
Possible workarounds for versions 4.x and 5.x:
- Check the certificate extracted via
getCertFromKeyInfoagainst trusted certificates before accepting the results of the validation. - Set
xml-crypto'sgetCertFromKeyInfoto() => undefinedforcingxml-cryptoto use an explicitly configuredpublicCertorprivateKeyfor signature verification.
PoC
https://github.com/node-saml/xml-crypto/discussions/399
Impact
An untrusted certificate can be used to pass a malicious XML payload through an improperly configured installation of xml-crypto.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | xml-crypto | ≥ 4.0.0&&< 6.0.0 | 6.0.0npm install xml-crypto@6.0.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for xml-crypto, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update xml-crypto to 6.0.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-2xp3-57p7-qf4v is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
Red Hat Developer Hub is not affected by this vulnerability because it does not use a vulnerable version of xml-crypto.
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.Source: Red Hat security advisory for GHSA-2xp3-57p7-qf4v (CC BY 4.0)
Frequently Asked Questions
Is GHSA-2xp3-57p7-qf4v in your dependencies?
Find it across npm, including transitive dependencies.