Skip to main content
Loading…
    CVE-2026-44729 — Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any — CVE Database · The Intelligence Room