GHSA-mfcp-34xw-p57x is a medium-severity (CVSS 6.8) vulnerability in saml2-js. A fix is available for saml2-js — see the affected versions and patch details below.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
saml2-jsnpmDescription
Versions of saml2-js prior to 2.0.5 are vulnerable to an Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.
Recommendation
Upgrade to version 2.0.5 or later.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | saml2-js | all versions | 2.0.5npm install saml2-js@2.0.5 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for saml2-js, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update saml2-js to 2.0.5 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-mfcp-34xw-p57x is resolved across your whole dependency graph.
Workarounds
Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.
Frequently Asked Questions
Is GHSA-mfcp-34xw-p57x in your dependencies?
Find it across npm, including transitive dependencies.