VYPR

Novu

by Novu

Source repositories

CVEs (4)

  • CVE-2026-75517MedSep 22, 2026
    risk 0.35cvss 6.5epss 0.01

    Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look up an integration by integrationId and…

  • CVE-2026-75511MedSep 22, 2026
    risk 0.27cvss —epss 0.00

    Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event payload.webhookUrl, and event overrides.webhookUrl, then passes the selected…

  • CVE-2026-75510MedSep 22, 2026
    risk 0.26cvss —epss 0.00

    Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and pass it through…

  • CVE-2023-35948MedJul 6, 2023
    risk 0.00cvss 5.4epss 0.00

    Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality of Novu's open-source repository. It could have allowed an attacker to force a victim into opening…