Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authenticated attacker to upload an HTML file containing JavaScript, which will be rendered by the victim's browser in the context of the Twenty CRM domain when accessed — enabling session hijacking, account takeover, and data theft.
🚨*CVE*
CVE-2026-44729 Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStr… https://www.cve.org/CVERecord?id=CVE-2026-44729
-----
Traducción:
CVE-2026-44729 Twe… http://infoflow.cloud`
Post summary
The message refers to CVE-2026-44729 for an open-source CRM, noting a file-serving issue, but offers only a basic description and a link to the CVE record, with no exploit code, patch, or technical details provided.
CVE-2026-44729 Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStr… https://www.cve.org/CVERecord?id=CVE-2026-44729
Post summary
The text references CVE‑2026‑44729, noting that versions 1.18.0 and earlier of Twenty CRM’s file‑serving endpoints are affected, but it provides no exploit, patch, or detailed technical data.