In-App Notification Vulnerability in Novu's API Client
CVE-2026-75510
5.1MEDIUM
What is CVE-2026-75510?
The Novu API prior to version 3.18.0 contains a vulnerability where the In-App Inbox and React Inbox component fail to validate the URL scheme in notification call-to-action redirects. This allows authenticated users to store a malicious 'javascript:' redirect that can be executed when other users click on notifications. Such an action could lead to exposure of sensitive session information and may allow unauthorized actions within the customer's application or the Novu dashboard. This vulnerability has been addressed in the latest version, making it essential for users to update to version 3.18.0 or above to mitigate the risk.
Affected Version(s)
novu < 3.18.0
