ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.
The vulnerability results from insufficient input sanitization in the /saml-post endpoint of the Login V2 interface, which classifies it as CWE-79 (Cross-site Scripting). An attacker can inject malicious JavaScript code that will be executed in the victim's browser within the context of the Zitadel application. Since the attack vector requires user interaction (UI:R), the exploit must trick the victim into visiting a crafted link or page. The attack scope extends beyond the original security context (S:C — Scope Changed), which increases its potential impact.
A successful attack could lead to user account takeover through session or authentication token theft. The attacker gains high-level access to sensitive data (C:H) and the ability to modify content in the context of the victim's browser (I:H).
Zitadel should be updated to version 4.12.0, where the vulnerability has been patched. Details are available in the official security advisory from the vendor at: https://github.com/zitadel/zitadel/security/advisories/GHSA-pr34-2v5x-6qjq
Zitadel versions 4.0.0 through 4.11.1 (inclusive) using the Login V2 interface.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NZitadel
APPZitadel4.0.0 – 4.12.0 (excl.)
Related vulnerabilities
SSRF bez uwierzytelnienia w ZITADEL — odczyt wewnętrznych zasobów sieciowych
IDOR w Zitadel Admin API umożliwia modyfikację wrażliwych ustawień
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerabil...
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel'...
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provid...