CVE-2026-75510
— UNSCOREDpublic exploit availablePublished 2026-09-22 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through apps/api/src/app/inbox/utils/notification-mapper.ts and packages/js/src/ui/components/Notification/DefaultNotification.tsx to the navigate function in packages/js/src/ui/context/InboxContext.tsx without validating its URL scheme. An authenticated organization member or environment API-key holder can store a javascript: redirect with target _self in an in-app workflow. When a recipient using a Chromium-based browser clicks the notification, window.open executes the redirect in the current inbox-hosting origin, which can expose session material and permit authenticated actions in a customer application or the self-hosted Novu dashboard. This issue is fixed in version 3.18.0.
Weaknesses
CWE-79
Public exploit & PoC references
- https://github.com/novuhq/novu/commit/f105f3d41a4405a75f803634d49f15a967524d8a
- https://github.com/novuhq/novu/pull/11453
- https://github.com/novuhq/novu/releases/tag/v3.18.0
- https://github.com/novuhq/novu/security/advisories/GHSA-8gr3-5j6f-25gp
- https://github.com/novuhq/novu/security/advisories/GHSA-8gr3-5j6f-25gp
All references
- https://github.com/novuhq/novu/commit/f105f3d41a4405a75f803634d49f15a967524d8a
- https://github.com/novuhq/novu/pull/11453
- https://github.com/novuhq/novu/releases/tag/v3.18.0
- https://github.com/novuhq/novu/security/advisories/GHSA-8gr3-5j6f-25gp
- https://github.com/novuhq/novu/security/advisories/GHSA-8gr3-5j6f-25gp
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-13533PoC
- MEDIUMCVE-2025-14814
- LOWCVE-2025-15677
- MEDIUMCVE-2025-15696
- LOWCVE-2025-15698
- MEDIUMCVE-2025-36147
- HIGHCVE-2025-61682PoC
- MEDIUMCVE-2025-71419PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.