Novu is an open-source notification and messaging platform, with its vulnerability footprint concentrated in a single product core. The observed weakness pattern centers on URL redirection controls, reflecting the application's role in handling external links and user-driven navigation flows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Novu over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35948MEDIUM Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality | Jul 6, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Novu.
Media articles that mention a CVE ID that affects a product developed by Novu — matched by CVE ID, not by vendor name.