In-App Notification Vulnerability in Novu's API Client
CVE-2026-75510

5.1MEDIUM

Key Information:

Vendor

Novuhq

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-75510?

The Novu API prior to version 3.18.0 contains a vulnerability where the In-App Inbox and React Inbox component fail to validate the URL scheme in notification call-to-action redirects. This allows authenticated users to store a malicious 'javascript:' redirect that can be executed when other users click on notifications. Such an action could lead to exposure of sensitive session information and may allow unauthorized actions within the customer's application or the Novu dashboard. This vulnerability has been addressed in the latest version, making it essential for users to update to version 3.18.0 or above to mitigate the risk.

Affected Version(s)

novu < 3.18.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.