PT-2026-96789 · Novu · Novu

CVE-2026-75511

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Novu versions prior to 3.18.0
Description Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event payload.webhookUrl, and event overrides.webhookUrl. These values are processed through send-message-chat.usecase.ts and sent as raw HTTP requests to providers including Slack, Discord, Mattermost, Microsoft Teams, Grafana On-Call, Ryver, Rocket.Chat, GetStream, and Zulip. Because these paths do not implement normalizeOutboundHttpUrl, assertSafeOutboundUrl, or DNS-pinned safeOutboundJsonRequest protections, an authenticated user can specify internal or restricted destinations. This allows the Novu worker to issue attacker-directed POST requests to internal network services, potentially triggering unauthorized interactions or actions.
Recommendations Update to version 3.18.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75511
GHSA-PG9Q-8V57-HQPH

Affected Products

Novu