It’s XML, so the signature inside the document somewhere and signs some other part of the document by reference.
You would be shocked (or, if you’re in the security space at all, not even remotely shocked) to learn that a comical number of SAML implementations verified the signature and then just treated the whole doc as if it was trusted, even if the signed part had nothing to do with the document as a whole.
Reminds me of a similar attack on PGP/MIME/HTML where you'd put <a href="http://evil.example/ in front of the PGP message.
Email's in a bad situation with regards to this because every intermediate server is expected to mangle the message and the headers, so the only way to consistently sign something is to make it a marked up encoded block the way PGP does.
You would be shocked (or, if you’re in the security space at all, not even remotely shocked) to learn that a comical number of SAML implementations verified the signature and then just treated the whole doc as if it was trusted, even if the signed part had nothing to do with the document as a whole.