CVE-2025-29775 is a signature verification bypass vulnerability in xml-crypto, an XML digital signature and encryption library for Node.js. Affected versions prior to 6.0.1, 3.2.1, and 2.1.6 can incorrectly accept a modified signed XML document as valid during verification. The flaw allows an attacker to alter a valid signed XML message while preserving a verification outcome that the application treats as trustworthy. In deployments that use xml-crypto to validate security assertions or other signed XML data, this can undermine the integrity guarantees of XML signatures and permit tampering with security-relevant fields such as identity or authorization attributes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a lab environment and exploit tool for demonstrating the SAMLStorm vulnerability (CVE-2025-29775) affecting the xml-crypto library and SAML implementations in Node.js. The main exploit is implemented in 'exploit/exploit.js', which runs a web server on http://localhost:8000. The tool allows a user to paste a base64-encoded SAML response, modifies the NameID to 'admin', recalculates the digest for the modified assertion, and inserts the new digest as an XML comment before the original DigestValue. This crafted response can then be submitted to a vulnerable Service Provider (http://localhost:3000 in the lab) to bypass XML signature verification and authenticate as an arbitrary user. The repository includes a full Node.js environment with dependencies, but the core exploit logic is in a single JavaScript file. The exploit is operational and demonstrates a real-world authentication bypass scenario for educational purposes.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content lists CVE-2025-29775 as a critical xml-crypto DigestValue bypass vulnerability, but provides no further technical detail.
An XML signature handling flaw in xml-crypto referenced as part of related 2025 vulnerabilities affecting the Node-SAML ecosystem.
Signature validation bypass in the Node.js xml-crypto library that can allow tampering with signed XML while still passing verification, enabling authentication/authorization bypass and potential privilege escalation/impersonation in systems relying on xml-crypto.
A SAML-related vulnerability mentioned in passing as part of the broader set of recently disclosed SAML issues; the content provides no additional detail.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.