CVE-2026-44729General(twenty / twenty)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authenticated attacker to upload an HTML file containing JavaScript, which will be rendered by the victim's browser in the context of the Twenty CRM domain when accessed — enabling session hijacking, account takeover, and data theft.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • twenty

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
twenty

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-26: 2Mentions · 2026-05-27: 1Technical Details · 2026-05-27: 105-2605-27
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-262
General2
2026-05-271
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Twenty CRM, Stored Cross-Site Scripting (XSS), #CVE-2026-44729 (Critical) https://dailycve.com/twenty-crm-stored-cross-site-scripting-xss-cve-2026-44729-critical/

    Post summary

    A critical stored XSS vulnerability (CVE‑2026‑44729) has been disclosed in Twenty CRM.

    0000077
    207 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-44729 Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStr… https://www.cve.org/CVERecord?id=CVE-2026-44729 ----- Traducción: CVE-2026-44729 Twe… http://infoflow.cloud`

    Post summary

    The message refers to CVE-2026-44729 for an open-source CRM, noting a file-serving issue, but offers only a basic description and a link to the CVE record, with no exploit code, patch, or technical details provided.

    0000045
    79 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44729 Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStr… https://www.cve.org/CVERecord?id=CVE-2026-44729

    Post summary

    The text references CVE‑2026‑44729, noting that versions 1.18.0 and earlier of Twenty CRM’s file‑serving endpoints are affected, but it provides no exploit, patch, or detailed technical data.

    00000246
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptwentytwenty---

Explore more