CVE-2026-44729
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authenticated attacker to upload an HTML file containing JavaScript, which will be rendered by the victim's browser in the context of the Twenty CRM domain when accessed — enabling session hijacking, account takeover, and data theft.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.37%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1189Drive-by Compromiseinitial access85 % - Impacto principal
T1059.007JavaScriptexecution90 % - Impacto secundario
T1078Valid Accountsstealth · persistence · privilege escalation · initial access70 % - Impacto secundario
T1556Modify Authentication Processdefense impairment · persistence · credential access75 %
XSS reflejado via upload de HTML/JS sin headers de seguridad (Content-Type, X-Content-Type-Options) permite ejecución de JavaScript en navegador (T1059.007), captura de sesiones (T1556) y robo de credenciales (T1078) en el contexto del dominio de Twenty CRM.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-44729",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44729",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-27T13:49:29.782751Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.7,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.8,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "twentyhq",
"product": "twenty",
"versions": [
{
"status": "affected",
"version": "<= 1.18.0"
}
]
}
]
}
],
"published": "2026-05-26T17:16:46.837",
"references": [
{
"url": "https://github.com/twentyhq/twenty/security/advisories/GHSA-f5h2-3qw5-3qp7",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/twentyhq/twenty/security/advisories/GHSA-f5h2-3qw5-3qp7",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authenticated attacker to upload an HTML file containing JavaScript, which will be rendered by the victim's browser in the context of the Twenty CRM domain when accessed — enabling session hijacking, account takeover, and data theft."
},
{
"lang": "es",
"value": "Twenty es un CRM de código abierto. En la versión 1.18.0 y anteriores, los puntos finales de servicio de archivos en Twenty CRM en /files/* y /file/:fileFolder/:id sirven archivos subidos usando fileStream.pipe(res) sin establecer ningún encabezado de respuesta Content-Type, Content-Disposition o X-Content-Type-Options. Esto permite a un atacante autenticado subir un archivo HTML que contenga JavaScript, el cual será renderizado por el navegador de la víctima en el contexto del dominio de Twenty CRM cuando se acceda a él - lo que posibilita el secuestro de sesión, la toma de control de cuenta y el robo de datos."
}
],
"lastModified": "2026-07-24T11:10:00.170",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:twenty:twenty:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD331BA5-5287-430D-9EE5-C3530D6415F9",
"versionEndIncluding": "1.18.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}