Junglewise Threat Intelligence

CVE-2026-33975: Twenty CRM SSRF bypass via IPv4-mapped IPv6 normalization

CVE-2026-33975 · Severity: info · CVSS 8.3 · Published 2026-05-05

Vendors: Twenty.

Executive brief

Twenty, an open-source CRM platform, contains a security flaw that allows authenticated users to bypass protections designed to prevent the server from making unauthorized internal requests. By using specially formatted web addresses, an attacker can force the server to connect to private internal systems or cloud management services. This could lead to the theft of sensitive cloud credentials (such as AWS IAM keys) or unauthorized access to internal company data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Twenty versions 1.18.0 and earlier due to a normalization mismatch between the Node.js URL parser and the application's 'isPrivateIp' utility. While the URL parser normalizes IPv4-mapped IPv6 addresses to compressed hexadecimal form (e.g., ::ffff:a9fe:a9fe), the validation utility only checks for dotted-decimal notation, allowing the hex-encoded private IPs to bypass security filters. Furthermore, because these are IP literals, the secondary socket lookup validation layer is bypassed as no DNS resolution occurs. An authenticated attacker can exploit this to reach internal services or cloud metadata services (IMDS) to exfiltrate sensitive credentials like IAM keys.

Affected products

  • twentyhq twenty-server <= 1.18.0

Timeline

  • 2026-04-27: advisory: GitHub Security Advisory published by maintainers
  • 2026-05-05: disclosed: CVE-2026-33975 published

References