CVE-2026-46490 affects samlify, a Node.js library for SAML single sign-on, in versions prior to 2.13.0. The flaw is caused by improper escaping during template substitution: samlify escapes attribute contexts but does not escape values inserted into XML element text, including locations such as saml:AttributeValue. As a result, a normal user who can control an attribute value such as email or name can inject XML markup that breaks out of the intended element content and inserts additional saml:Attribute elements into the SAML assertion. The identity provider then signs the tampered assertion, and the service provider accepts the injected attributes as trusted because they are covered by a valid signature. This creates an XML injection condition in signed SAML assertions that can be abused to alter authorization-relevant claims.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept for CVE-2026-46490 affecting samlify versions before 2.13.0. It is not part of a major exploit framework. The repo contains one main exploit script (poc.js), one setup helper (setup.sh), package metadata, and documentation (README.md and ANALYSIS.md) explaining the root cause and impact. The exploit demonstrates XML injection in samlify's template substitution logic for SAML assertions. The vulnerable behavior is that placeholder values are XML-escaped only when preceded by a double quote, which protects attribute contexts but not element-text contexts. Because SAML attribute values are inserted into <saml:AttributeValue>{Value}</saml:AttributeValue>, attacker-controlled content is emitted unescaped. The PoC abuses this by supplying a malicious email value that closes the current AttributeValue and Attribute elements, inserts a forged <saml:Attribute Name="role"><saml:AttributeValue>admin</saml:AttributeValue></saml:Attribute>, and then opens a throwaway attribute to keep the final XML balanced. Operationally, poc.js sets up a local samlify Identity Provider and Service Provider using generated certificates. It calls idp.createLoginResponse() with a custom replacement callback that injects the malicious attrEmail value into the SAML template before signing. The script then base64-decodes the resulting SAMLResponse, verifies that the forged role attribute is present in the signed assertion, and finally feeds the response into samlify's SP parser. The SP validates the IdP signature and extracts attributes, demonstrating that role=admin is accepted as authoritative. This confirms the exploit capability: privilege escalation through attacker-controlled, signature-valid forged SAML attributes. Repository structure and purpose: - poc.js: primary exploit logic and end-to-end demonstration. - setup.sh: installs dependencies and generates IdP/SP keypairs for the lab. - package.json: pins samlify 2.12.0 and XML validator dependency. - README.md: vulnerability overview, reproduction steps, impact, and remediation. - ANALYSIS.md: code-level explanation of the vulnerable substitution heuristic and why signing does not mitigate the issue. Overall, this is a real, functional PoC exploit for a web/network authentication trust boundary issue in SAML deployments, specifically showing authenticated low-privilege privilege escalation against Service Providers that trust assertions from a vulnerable samlify-based IdP.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.