MEDIUM
Twenty: Stored XSS via BlockNote FileBlock
Published Apr 21, 2026
5.7
MEDIUMCVSS 3.1
EPSS 0.42%
Description
Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock component and insufficient server-side inspection of block content, an attacker can inject a javascript: URI into the url property of a file block. This allows the execution of arbitrary JavaScript when a user clicks on the malicious file attachment. This vulnerability is fixed in 1.20.6.
Affected products
-
- Version < 1.20.6StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24161 Advisory
- https://github.com/twentyhq/twenty/commit/8da69e0f77ea820a6845a4c3c025b6af3861d523 x_refsource_MISC
- https://github.com/twentyhq/twenty/security/advisories/GHSA-7w89-7q26-gj7q exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24161 | Advisory | |
| https://github.com/twentyhq/twenty/commit/8da69e0f77ea820a6845a4c3c025b6af3861d523 | x_refsource_MISC | |
| https://github.com/twentyhq/twenty/security/advisories/GHSA-7w89-7q26-gj7q | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 21, 2026
Reserved Apr 2, 2026
Link CVE-2026-35451
CISA Vulnrichment
Updated Apr 21, 2026
ENISA EUVD
EUVD-2026-24161 Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 21, 2026
Exploited since n/a
Link EUVD-2026-24161