Executive brief
Novu's email workflow editor has a cross-site scripting (XSS) vulnerability where dangerous HTML attributes like oncontentvisibilityautostatechange are not properly filtered from email templates. An attacker can craft a malicious email template containing JavaScript that executes when the template is previewed, potentially compromising dashboard access or stealing session data of users editing email templates.
Technical details
The vulnerability exists in the sanitizer service used by Novu's application layer. The sanitize-html library is configured with allowedAttributes: false, which paradoxically permits all attributes through initially. A DANGEROUS_ATTRIBUTES blocklist attempts to filter dangerous event handlers post-sanitization, but the list is incomplete and misses attributes like oncontentvisibilityautostatechange. An attacker with dashboard access can inject a crafted HTML anchor tag with this payload into an email step body, which executes arbitrary JavaScript in the context of the dashboard when the email preview renders. While this appears as stored XSS, the attack can be amplified if an attacker uses OAuth flows to trick victims into logging into a compromised account with pre-placed payloads. The vulnerability is patched in version 3.15.0 and later.
Affected products
- Novu Novu API < 3.15.0
- Novu Novu Worker < 3.15.0
Timeline
- 2026-04-13: disclosed: Advisory published by Novu security team
- 2026-04-14: patched: Fixed in version 3.15.0