CVE-2025-46572 | auth0 passport-wsfed-saml2 up to 4.6.3 SAML2 Authentication improper authentication (GHSA-wjmp-wphq-jvqf)
A vulnerability classified as critical was found in auth0 passport-wsfed-saml2 up to 4.6.3. Affected by this vulnerability is an unknown functionality of the component SAML2 Authentication. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2025-46572. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.