Back

CRITICAL

Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution

Published Aug 11, 2026

Description

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/workspace-schema-manager/utils/build-sql-column-definition.util.ts to concatenate unescaped input into GENERATED ALWAYS AS (...) and execute arbitrary PostgreSQL statements as the application database user. This issue is fixed in version 2.15.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026

CISA Vulnrichment

Updated Aug 11, 2026

NVD

Status Deferred
Modified Sep 9, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026

GitHub

No data