Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8gr3-5j6f-25gp | Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme |
Tue, 22 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Novu
Novu novu |
|
| Vendors & Products |
Novu
Novu novu |
Tue, 22 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through apps/api/src/app/inbox/utils/notification-mapper.ts and packages/js/src/ui/components/Notification/DefaultNotification.tsx to the navigate function in packages/js/src/ui/context/InboxContext.tsx without validating its URL scheme. An authenticated organization member or environment API-key holder can store a javascript: redirect with target _self in an in-app workflow. When a recipient using a Chromium-based browser clicks the notification, window.open executes the redirect in the current inbox-hosting origin, which can expose session material and permit authenticated actions in a customer application or the self-hosted Novu dashboard. This issue is fixed in version 3.18.0. | |
| Title | Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T15:59:27.761Z
Reserved: 2026-08-17T20:49:21.598Z
Link: CVE-2026-75510
Updated: 2026-09-22T15:59:24.621Z
Status : Received
Published: 2026-09-22T16:17:53.950
Modified: 2026-09-22T16:17:53.950
Link: CVE-2026-75510
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:00:12Z

Github GHSA