Skip to main content

CVE-2025-29774 and CVE-2025-29775 (SAMLStorm)

Disclosure for CVE-2025-29774 and CVE-2025-29775 (SAMLStorm).

A vulnerability in an open-source library, xml-crypto, which Retool uses for SAML login implementation, allowed for account takeovers through forged SAML identity provider (IdP) assertions. In the worst case, an external threat actor could forge arbitrary assertions for a SAML IdP, potentially leading to full account takeovers within an organization.

This exploit requires no user interaction and an attacker could gain unauthorized access to an organization with escalated privileges. More information about these vulnerabilities is available on the WorkOS website.

FieldValue
Vulnerability TypeImproper Verification of Cryptographic Signature
Packagexml-crypto
Affected ComponentRetool organizations using SAML SSO
Attack TypeRemote
ImpactAccount Takeover
Referencehttps://workos.com/blog/samlstorm
DiscovererAlexander Tan (ahacker1)

Fixed release versions

BranchVersions
Edge3.170.0-edge
Stable3.148.3-stable
Stable3.114.16-stable

Affected release versions

Release branchRelease versions
Edge3.149.0 to 3.168.0
3.148-stable3.148.0 to 3.148.2
Edge3.111.0 to 3.144.0
3.114-stable3.114.0 to 3.114.15
< 3.111.0