CVE-2025-29774 is a critical vulnerability in the xml-crypto Node.js library (versions prior to 6.0.1, 3.2.1, and 2.1.6) that allows attackers to bypass authentication or authorization by modifying signed XML documents without invalidating the signature. This flaw, rated 9.3 Critical, enables privilege escalation or user impersonation by altering critical identity attributes. While no active exploitation, public exploit code, or significant community discussion has been observed, the high severity and potential for significant impact necessitate immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Node-Saml | Xml-Crypto | < 2.1.6, >= 3.0.0, < 3.2.1, >= 4.0.0, < 6.0.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.