Server-Side Request Forgery (SSRF) in Twenty - CVE-2026-27023
Published: July 28, 2026
Twenty
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information from internal network services.
The vulnerability exists due to server-side request forgery in SecureHttpClientService when following HTTP redirects for outbound requests. A remote user can supply a URL that redirects to an internal network address to disclose sensitive information from internal network services.
Cross-protocol redirects from HTTPS to HTTP can bypass the configured agent, and exploitability depends on the deployment environment and reachable internal services.