CVE-2026-82274: Twentyhq Twenty
Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect users to arbitrary hosts while forwarding OAuth authorization codes, bypassing domain validation when IS_MULTIWORKSPACE_ENABLED is disabled.
Affected products
- Twentyhq Twenty: up to and including 2.35.0
Published 2026-08-28. Last modified 2026-09-23.