
We took a closer look at Twenty CRM’s serverless functions while analyzing CVE-2026-26720 and found something far more serious than expected. A “custom code” feature ends up running user-supplied TypeScript directly on the server, with no real sandbox, full environment access, and no meaningful restrictions on what can be executed. When you combine that with unauthenticated webhook triggers, it becomes possible to go from a normal workspace member to full server compromise and a persistent backdoor. This is another example of how fast “flexible” platform features turn into security boundaries when isolation is missing. Full technical breakdown in the article: https://blog.ostorlab.co/cve-2026-26720-twenty-crm-serverless-rce.html
Post summary
The post announces CVE-2026-26720, revealing that Twenty CRM’s serverless feature executes unsandboxed user‑supplied TypeScript and can be triggered without authentication, enabling full server compromise. A technical article link is provided for detailed analysis.



