© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
NovuN
Novu•12mo ago•
3 replies
Rot4tion

Security Concerns in Novu: Preventing Unauthorized Notification Access

I'm a beginner using Novu, and I have a security-related question. An attacker only needs the
NOVU_APPLICATION_IDENTIFIER
NOVU_APPLICATION_IDENTIFIER
and
subscriberId
subscriberId
to listen to a victim's notifications, and both of these are easily obtainable because
NOVU_APPLICATION_IDENTIFIER
NOVU_APPLICATION_IDENTIFIER
is exposed on the client side, and subscriberId in SQL databases is often an incrementing number, making it predictable.

Novu's current security solution for this issue is to use
subscriberHash
subscriberHash
when connecting. However, an attacker can modify the client code to connect without including
subscriberHash
subscriberHash
since there is no configuration on Novu's host that enforces a requirement for
subscriberHash
subscriberHash
to be present when users connect.
Novu banner
NovuJoin
Open Source Notification Infrastructure Community by Novu
4,169Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Novu Access Query
NovuNNovu / 💬│support
12mo ago
Custom In-App Popup on New Notification using @novu/notification-center
NovuNNovu / 💬│support
7mo ago
Notification Payload Not Overriding Dummy Data in Novu
NovuNNovu / 💬│support
8mo ago
Workflow Considerations for Multiple Notification Types in Novu
NovuNNovu / 💬│support
11mo ago