CVE-2026-105763 is a critical vulnerability in the Twenty open-source CRM platform. A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. The vulnerability exists in versions 1.20.10 through 2.6.0 of the Twenty platform. Google and Microsoft OAuth-only workspaces were not affected. This issue [truncated]
CVE-2026-92771 is a high-severity vulnerability in Twenty before version 2.35.0, allowing authenticated users to bypass permission checks in the groupBy-with-records GraphQL resolver. This issue enables attackers with canReadObjectRecords permission but lacking canReadFieldValue access to retrieve restricted field values. The vulnerability was published on 2026-09-16T21:17:25.750Z and last modified on 202 [truncated]
CVE-2026-82274 is a medium-severity vulnerability affecting twentyhq's Twenty product versions 2.20 through 2.35.0. The issue is an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint. This vulnerability allows attackers to craft malicious requests that can redirect users to arbitrary hosts while forwarding OAuth authorization codes, bypassing domain validation whe [truncated]
A critical vulnerability was found in Twenty, an open-source CRM platform, which allows a workspace administrator with the DATA_MODEL permission to execute arbitrary PostgreSQL statements as the application database user. This issue is fixed in version 2.15.0. The vulnerability exists due to improper input validation in the buildSqlColumnDefinition function, allowing for potential code execution and data [truncated]
A critical remote code execution vulnerability exists in Twenty CRM versions 1.7.7 through 1.16.7. The vulnerability stems from unsanitized user input in the timeZone parameter of the REST API groupBy endpoint, where the parameter is directly interpolated into raw SQL using JavaScript template literals without parameterization, validation, or escaping. An authenticated attacker can exploit this SQL inject [truncated]
## Summary Twenty CRM versions 1.18.0 and earlier contain a stored cross-site scripting (XSS) vulnerability in file serving endpoints. The application serves uploaded files without setting security headers (Content-Type, Content-Disposition, X-Content-Type-Options), allowing authenticated attackers to upload HTML files with embedded JavaScript that executes in the victim's browser within the Twenty CRM do [truncated]