Descrição
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authenticated attacker to upload an HTML file containing JavaScript, which will be rendered by the victim-s browser in the context of the Twenty CRM domain when accessed — enabling session hijacking, account takeover, and data theft.
CVSS 8.7EPSS 0.258%Risco 0.89
Ver fonte- Publicação
- 2026-05-26 17:16:46
- Versões afetadas
- <=1.18.0
- Tipo
- Core software
- Última alteração
- 2026-07-24 11:10:00
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N