CVE-2026-82274
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect users to arbitrary hosts while forwarding OAuth authorization codes, bypassing domain validation when IS_MULTIWORKSPACE_ENABLED is disabled.
601
URL Redirection to Untrusted Site ('Open Redirect')
DraftCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Other
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Other
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/twentyhq/twenty/issues/22109
https://github.com/twentyhq/twenty
https://github.com/twentyhq/twenty/blob/5851753d0cad4678af94382899d371203d651ac…
https://github.com/twentyhq/twenty/issues/22109
https://www.vulncheck.com/advisories/twenty-open-redirect-via-oauth-propagator-…