CVE-2023-35948 is an open redirect vulnerability affecting Novu versions prior to 0.16.0, specifically within the "Sign In with GitHub" functionality of its open-source repository. This medium-severity vulnerability (CVSS 6.1) could allow an attacker to redirect users to malicious URLs, potentially leading to account compromise if GitHub OAuth was enabled. The attack requires user interaction and has low complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.16CPE matchmatch criteria | cpe:2.3:a:novu:novu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.