PT-2026-96789 · Novu · Novu
CVE-2026-75511
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Novu versions prior to 3.18.0
Description
Novu accepts chat webhook URLs from
subscriber credentials.webhookUrl, channel endpoint endpoint.url, event payload.webhookUrl, and event overrides.webhookUrl. These values are processed through send-message-chat.usecase.ts and sent as raw HTTP requests to providers including Slack, Discord, Mattermost, Microsoft Teams, Grafana On-Call, Ryver, Rocket.Chat, GetStream, and Zulip. Because these paths do not implement normalizeOutboundHttpUrl, assertSafeOutboundUrl, or DNS-pinned safeOutboundJsonRequest protections, an authenticated user can specify internal or restricted destinations. This allows the Novu worker to issue attacker-directed POST requests to internal network services, potentially triggering unauthorized interactions or actions.Recommendations
Update to version 3.18.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novu