Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2025-47949: samlify library may allow unauthorized access
CVE-2025-47949 · published 1 day ago
Summary
The samlify code that many web applications use to handle login messages could be abused to gain access without permission. This could let attackers view or change sensitive data. Install the latest samlify version released by the vendor to eliminate the risk.
What to do
- Update tngan samlify to version 2.10.0.
- Update rootio @rootio/samlify to version 2.10.0-root.io.1.
- Update tngan samlify to version 2.10.0-aikido.1.
- Update samlify to version 2.10.0-aikido.1.
- Update samlify_project samlify to version 2.10.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | tngan | samlify |
< 2.10.0 Fix: upgrade to 2.10.0
|
| – | samlify_project | samlify |
< 2.10.0 cpe:2.3:a:samlify_project:samlify:*:*:*:*:*:*:*:* |
| Root:npm | rootio | @rootio/samlify |
< 2.10.0-root.io.1 Fix: upgrade to 2.10.0-root.io.1
|
| Root:npm | tngan | samlify |
< 2.10.0-aikido.1 Fix: upgrade to 2.10.0-aikido.1
|
| Root:npm | – | samlify |
< 2.10.0-aikido.1 Fix: upgrade to 2.10.0-aikido.1
|
Original advisory text
CVE-2025-47949 in samlify - Patched by Root
Root has patched CVE-2025-47949 in the samlify package for Root:npm. Multiple fixed versions available.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta