CVE-2026-82274: Twentyhq Twenty

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect users to arbitrary hosts while forwarding OAuth authorization codes, bypassing domain validation when IS_MULTIWORKSPACE_ENABLED is disabled.

Affected products

  • Twentyhq Twenty: up to and including 2.35.0

Published 2026-08-28. Last modified 2026-09-23.