twentyhq twenty

3 known vulnerabilities in twentyhq twenty, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-85055 CVSS 7.1 high Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on…
  • CVE-2026-92771 CVSS 7.1 high Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated…
  • CVE-2026-82274 CVSS 5.3 medium Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats…