GHSA-26wg-9xf2-q495: Novu has a XSS sanitization bypass
XSS sanitization is incomplete, some attributes are missing such as oncontentvisibilityautostatechange=. This allows for the email preview to render HTML that executes arbitrary JavaScript,
References
Code Behaviors & Features
Detect and mitigate GHSA-26wg-9xf2-q495 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →