PatchSiren

twentyhq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL twentyhq CVE published 2026-10-05

CVE-2026-105763

CVE-2026-105763 is a critical vulnerability in the Twenty open-source CRM platform. A normal workspace member could obtain other members' external-service credentials and use them to access mail or calendars and potentially reset third-party accounts. The vulnerability exists in versions 1.20.10 through 2.6.0 of the Twenty platform. Google and Microsoft OAuth-only workspaces were not affected. This issue [truncated]

HIGH twentyhq CVE published 2026-09-16

CVE-2026-92771

CVE-2026-92771 is a high-severity vulnerability in Twenty before version 2.35.0, allowing authenticated users to bypass permission checks in the groupBy-with-records GraphQL resolver. This issue enables attackers with canReadObjectRecords permission but lacking canReadFieldValue access to retrieve restricted field values. The vulnerability was published on 2026-09-16T21:17:25.750Z and last modified on 202 [truncated]

MEDIUM twentyhq CVE published 2026-08-28

CVE-2026-82274

CVE-2026-82274 is a medium-severity vulnerability affecting twentyhq's Twenty product versions 2.20 through 2.35.0. The issue is an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint. This vulnerability allows attackers to craft malicious requests that can redirect users to arbitrary hosts while forwarding OAuth authorization codes, bypassing domain validation whe [truncated]

CRITICAL twentyhq CVE published 2026-08-11

CVE-2026-73069

A critical vulnerability was found in Twenty, an open-source CRM platform, which allows a workspace administrator with the DATA_MODEL permission to execute arbitrary PostgreSQL statements as the application database user. This issue is fixed in version 2.15.0. The vulnerability exists due to improper input validation in the buildSqlColumnDefinition function, allowing for potential code execution and data [truncated]

CRITICAL twentyhq CVE published 2026-05-26

CVE-2026-46624

A critical remote code execution vulnerability exists in Twenty CRM versions 1.7.7 through 1.16.7. The vulnerability stems from unsanitized user input in the timeZone parameter of the REST API groupBy endpoint, where the parameter is directly interpolated into raw SQL using JavaScript template literals without parameterization, validation, or escaping. An authenticated attacker can exploit this SQL inject [truncated]

HIGH twentyhq CVE published 2026-05-26

CVE-2026-44729

## Summary Twenty CRM versions 1.18.0 and earlier contain a stored cross-site scripting (XSS) vulnerability in file serving endpoints. The application serves uploaded files without setting security headers (Content-Type, Content-Disposition, X-Content-Type-Options), allowing authenticated attackers to upload HTML files with embedded JavaScript that executes in the victim's browser within the Twenty CRM do [truncated]