Skip to main content
Loading…
    CVE-2026-33975 — Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addr — CVE Database · The Intelligence Room