PT-2026-83297 · Git+1 · Twenty

·

CVE-2026-82274

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Twenty versions prior to 2.35.0
Description An open redirect issue exists in the OAuthPropagatorController.propagateOAuthCallback endpoint. The system incorrectly treats the state query parameter as a redirect URL. When the IS MULTIWORKSPACE ENABLED variable is disabled, domain validation is bypassed, allowing attackers to craft requests that redirect users to arbitrary hosts while forwarding OAuth authorization codes.
Recommendations Update to version 2.35.0 or later. As a temporary mitigation, ensure the IS MULTIWORKSPACE ENABLED variable is enabled to maintain domain validation.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82274

Affected Products

Twenty