CVE-2026-75510

Source
https://cve.org/CVERecord?id=CVE-2026-75510
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75510.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75510
Aliases
Published
2026-09-22T15:47:19Z
Modified
2026-09-23T03:46:48Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
Details

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through apps/api/src/app/inbox/utils/notification-mapper.ts and packages/js/src/ui/components/Notification/DefaultNotification.tsx to the navigate function in packages/js/src/ui/context/InboxContext.tsx without validating its URL scheme. An authenticated organization member or environment API-key holder can store a javascript: redirect with target _self in an in-app workflow. When a recipient using a Chromium-based browser clicks the notification, window.open executes the redirect in the current inbox-hosting origin, which can expose session material and permit authenticated actions in a customer application or the self-hosted Novu dashboard. This issue is fixed in version 3.18.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75510.json"
}
References

Affected packages

Git / github.com/novuhq/novu

Affected ranges

Type
GIT
Repo
https://github.com/novuhq/novu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.18.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

@novu/api@2.*
@novu/api@2.6.5
@novu/client@2.*
@novu/client@2.6.5
@novu/framework@2.*
@novu/framework@2.6.5
@novu/framework@2.8.0
@novu/framework@2.9.0
@novu/framework@v2.*
@novu/framework@v2.11.1
@novu/headless@2.*
@novu/headless@2.6.5
@novu/js@2.*
@novu/js@2.6.5
@novu/js@v3.*
@novu/js@v3.0.3
@novu/js@v3.10.0
@novu/js@v3.10.1
@novu/js@v3.11.0
@novu/js@v3.11.2
@novu/js@v3.12.0
@novu/js@v3.13.0
@novu/js@v3.14.0
@novu/js@v3.14.1
@novu/js@v3.15.0
@novu/js@v3.16.0
@novu/js@v3.17.0
@novu/js@v3.18.0
@novu/js@v3.2.0
@novu/js@v3.3.0
@novu/js@v3.3.1
@novu/js@v3.4.0
@novu/js@v3.7.0
@novu/js@v3.8.1
@novu/js@v3.9.1
@novu/js@v3.9.2
@novu/js@v3.9.3
@novu/nextjs@2.*
@novu/nextjs@2.6.5
@novu/nextjs@v3.*
@novu/nextjs@v3.0.3
@novu/nextjs@v3.10.0
@novu/nextjs@v3.10.1
@novu/nextjs@v3.11.0
@novu/nextjs@v3.11.2
@novu/nextjs@v3.12.0
@novu/nextjs@v3.13.0
@novu/nextjs@v3.14.0
@novu/nextjs@v3.14.1
@novu/nextjs@v3.15.0
@novu/nextjs@v3.16.0
@novu/nextjs@v3.17.0
@novu/nextjs@v3.18.0
@novu/nextjs@v3.2.0
@novu/nextjs@v3.3.0
@novu/nextjs@v3.3.1
@novu/nextjs@v3.4.0
@novu/nextjs@v3.7.0
@novu/nextjs@v3.8.1
@novu/nextjs@v3.9.1
@novu/nextjs@v3.9.2
@novu/nextjs@v3.9.3
@novu/node@2.*
@novu/node@2.6.5
@novu/providers@2.*
@novu/providers@2.6.5
@novu/react-native@2.*
@novu/react-native@2.6.5
@novu/react-native@v3.*
@novu/react-native@v3.0.3
@novu/react-native@v3.10.0
@novu/react-native@v3.10.1
@novu/react-native@v3.11.0
@novu/react-native@v3.11.2
@novu/react-native@v3.12.0
@novu/react-native@v3.13.0
@novu/react-native@v3.14.0
@novu/react-native@v3.14.1
@novu/react-native@v3.15.0
@novu/react-native@v3.16.0
@novu/react-native@v3.17.0
@novu/react-native@v3.18.0
@novu/react-native@v3.2.0
@novu/react-native@v3.3.0
@novu/react-native@v3.3.1
@novu/react-native@v3.4.0
@novu/react-native@v3.7.0
@novu/react-native@v3.8.1
@novu/react-native@v3.9.1
@novu/react-native@v3.9.2
@novu/react-native@v3.9.3
@novu/react@2.*
@novu/react@2.6.5
@novu/react@v3.*
@novu/react@v3.0.3
@novu/react@v3.10.0
@novu/react@v3.10.1
@novu/react@v3.11.0
@novu/react@v3.11.2
@novu/react@v3.12.0
@novu/react@v3.13.0
@novu/react@v3.14.0
@novu/react@v3.14.1
@novu/react@v3.15.0
@novu/react@v3.16.0
@novu/react@v3.17.0
@novu/react@v3.18.0
@novu/react@v3.2.0
@novu/react@v3.3.0
@novu/react@v3.3.1
@novu/react@v3.4.0
@novu/react@v3.7.0
@novu/react@v3.8.1
@novu/react@v3.9.1
@novu/react@v3.9.2
@novu/react@v3.9.3
@novu/shared@2.*
@novu/shared@2.6.5
@novu/stateless@2.*
@novu/stateless@2.6.5
novu@2.*
novu@2.10.0
novu@2.6.5
v0.*
v0.0.2
v0.0.4
v0.1.1
v0.1.3
v0.1.4
v0.10.0
v0.11.0
v0.14.0
v0.16.4
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.3.4
v0.3.5
v0.3.5-alpha.0
v0.4.0-alpha.10
v0.4.0-alpha.11
v0.4.0-alpha.12
v0.4.0-alpha.2
v0.4.0-alpha.3
v0.4.0-alpha.4
v0.4.0-alpha.5
v0.4.0-alpha.6
v0.4.0-alpha.7
v0.4.0-alpha.8
v0.4.0-alpha.9
v0.4.1
v0.4.1-alpha.0
v0.4.2
v0.5.1
v0.6.0
v0.6.0-alpha.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.8.0
v1.*
v1.0.1
v2.*
v2.0.0
v2.0.1
v3.*
v3.12.0
v3.13.0
v3.14.0
v3.15.0
v3.17.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75510.json"