Cross-site scripting in Twenty - CVE-2026-35451
Published: July 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in the BlockNote FileBlock component when rendering crafted file block content. A remote user can inject a javascript: URI into the url property of a file block to execute arbitrary JavaScript in a victim's browser.
User interaction is required to click on the malicious file attachment.