CVE-2026-85055
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL or REST filter predicates. A workspace member or API key with permission to read an object but not a particular field can reference that denied field in direct filters, relation filters, or persisted view filters. The resulting totalCount and row presence reveal whether guesses match the real column, forming a boolean/count oracle that can reconstruct denied field values for records exposed by the principal's row-level policy. This issue is fixed in version 2.22.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| twentyhq | twenty | < 2.22.0 | affected |
Weaknesses
- CWE-200: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-285: CWE-285: Improper Authorization
References
- https://github.com/twentyhq/twenty/security/advisories/GHSA-v93q-4jcx-7p9m
- https://github.com/twentyhq/twenty/pull/22873
- https://github.com/twentyhq/twenty/commit/a5108d512f754a937860bda5e0c2c40c7266e19e
- https://github.com/twentyhq/twenty/releases/tag/twenty/v2.22.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.