🛡️ GHSA-4x48-cgf9-q33f — api

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-918 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection

Summary

The conditions filter webhook at libs/application-generic/src/usecases/conditions-filter/conditions-filter.usecase.ts line 261 sends POST requests to user-configured URLs using raw axios.post() with no SSRF validation. The HTTP Request workflow step in the same codebase correctly uses validateUrlSsrf() which blocks private IP ranges. The conditions webhook was not included in this protection.

Root Cause

conditions-filter.usecase.ts line 261:

```typescript

return await axios.post(child.webhookUrl, payload, config).then((response) => {

return response.data as Record<string, unknown>;

});

```

No call to validateUrlSsrf(). The webhookUrl comes from the workflow condition configuration with zero validation.

Protected Code (for contrast)

execute-http-request-step.usecase.ts line 130:

```typescript

const ssrfValidationError = await validateUrlSsrf(url);

if (ssrfValidationError) {

// blocked

}

```

This function resolves DNS and checks against private ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16). It exists in the codebase but is not applied to the conditions webhook path.

Proof of Concept

1. Create a workflow with a condition step

2. Configure the condition's webhook URL to http://169.254.169.254/latest/meta-data/iam/security-credentials/

3. Trigger the workflow by sending a notification event

4. The worker evaluates the condition and calls axios.post() to the metadata endpoint

5. The response data is stored in execution details and accessible via the execution details API

Impact

Full-read SSRF. The response body is returned as Record<string, unknown> for condition evaluation and stored in the execution details raw field. The GET /execution-details API returns this data.

The POST method limits some metadata endpoints (GCP requires GET, Azure requires GET), but AWS IMDSv1 accepts POST and returns credentials. Internal services accepting POST are also reachable.

Suggested Fix

Extract validateUrlSsrf() to a shared utility and call it before the axios.post in conditions-filter.usecase.ts:

```typescript

const ssrfError = await validateUrlSsrf(child.webhookUrl);

if (ssrfError) {

throw new Error('Webhook URL blocked by SSRF protection');

}

return await axios.post(child.webhookUrl, payload, config)...

```

Weakness class

GHSA-4x48-cgf9-q33f is classified as CWE-918: Server-Side Request Forgery (SSRF). The server fetches a URL supplied by the caller, which can be pointed at internal systems it alone can reach.

Affected software

GHSA-4x48-cgf9-q33f is recorded against 1 package.

  • @novu/api

Timeline and source

Published on 14 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Web)
github.com (Package)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector N/A
CWE CWE-918
Public Exploit ✅ No
Source OSV
Published 2026-04-14
Updated 2026-08-20
Modified 2026-04-14
Fix URL N/A

Affected Packages

Software From version Fixed in
@novu/api

Site Security Check

Is api part of your stack?

GHSA-4x48-cgf9-q33f is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesGitHub AdvisoryGitHub Advisory Undated