๐Ÿ” CVE Alert

CVE-2026-73069

CRITICAL 9.1

Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/workspace-schema-manager/utils/build-sql-column-definition.util.ts to concatenate unescaped input into GENERATED ALWAYS AS (...) and execute arbitrary PostgreSQL statements as the application database user. This issue is fixed in version 2.15.0.

CWE CWE-89
Vendor twentyhq
Product twenty
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for twentyhq twenty

Be the first to know when new critical vulnerabilities affecting twentyhq twenty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

twentyhq / twenty
< 2.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/twentyhq/twenty/security/advisories/GHSA-mm7j-q9q3-qqwj github.com: https://github.com/twentyhq/twenty/pull/21947 github.com: https://github.com/twentyhq/twenty/commit/0b8368cd6c1a47711bf52972800f162bde0bbab9