Executive brief
Twenty is an open-source Customer Relationship Management (CRM) platform. A security flaw in how the system handles file uploads allows an attacker with basic user permissions to upload malicious HTML files. If another user, such as an administrator, views this file, the attacker can execute malicious code in their browser to steal login sessions, take over accounts, or access sensitive customer data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Twenty CRM versions 1.18.0 and earlier. The file-serving endpoints at `/files/*` and `/file/:fileFolder/:id` utilize `fileStream.pipe(res)` without defining `Content-Type`, `Content-Disposition`, or `X-Content-Type-Options` headers. Because Express.js does not automatically set a Content-Type when piping a stream, browsers perform MIME-sniffing and render uploaded HTML files inline. An authenticated attacker can upload a malicious HTML/JavaScript payload via the `uploadWorkflowFile` mutation. When a victim accesses the resulting URL, the script executes within the CRM's origin, enabling session hijacking and full account takeover.
Affected products
- Twenty Twenty CRM <= 1.18.0
Timeline
- 2026-05-05: advisory: Original GitHub security advisory published
- 2026-05-26: disclosed: CVE-2026-44729 published to NVD