SSRF Vulnerability in Twenty CRM Software
CVE-2026-27023
5MEDIUM
What is CVE-2026-27023?
Prior to version 1.18, Twenty, an open-source CRM, posed a security risk due to inadequate validation within its SecureHttpClientService. The SSRF protection implemented allowed authenticated users to manipulate outbound request URLs, which in turn compromised the blocking of private IP addresses through controlled URL redirection. This vulnerability enabled attackers to route requests via their servers, potentially exposing sensitive data or systems connected to those URLs. An update to version 1.18 effectively addresses this issue by enhancing validation processes for redirect targets.
Affected Version(s)
twenty < 1.18
