Executive brief
Novu, an open-source notification infrastructure platform, is vulnerable to a security flaw where its email editor fails to properly clean malicious code from user input. An attacker could use this to execute unauthorized scripts in the browser of another user who views a shared workflow or email template. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of the victim.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Novu due to an incomplete sanitization blacklist in the `sanitizer.service.ts` component. While the application uses `sanitize-html`, it was configured with `allowedAttributes: false` and relied on a custom `DANGEROUS_ATTRIBUTES` array that failed to include modern HTML attributes like `oncontentvisibilityautostatechange`. An attacker can bypass the filter by injecting these missing event handlers into email workflow steps. When a victim (such as another dashboard user) views the affected email step, the payload executes in their browser context. This can be further weaponized via OAuth login CSRF to force a victim into an attacker-controlled account containing the payload. The issue is fixed in version 3.15.0.
Affected products
- Novu Novu API < 3.15.0
Timeline
- 2026-04-13: disclosed
- 2026-04-14: advisory: GitHub Advisory GHSA-26wg-9xf2-q495 published
- 2026-04-14: patched: Fixed in version 3.15.0