Twenty CRM Server-Side Request Forgery Protection Bypass Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Twenty CRM versions prior to 1.18. The issue arises in the SecureHttpClientService, where SSRF protection only validated request URLs at the request level, neglecting redirect targets. This oversight allowed authenticated users who could manipulate outbound request URLs to bypass private IP blocking by redirecting through an attacker-controlled server. Exploitation could lead to unauthorized access to internal network services, including cloud metadata endpoints.

Impact

Exploitation of this vulnerability could allow an authenticated attacker to read responses from internal network services, potentially including sensitive cloud metadata.

Remediation

The vulnerability has been fixed in version 1.18 by moving IP validation from the request level to the connection level, ensuring that all TCP connections, including redirects, are properly validated.

Added: Mar 5, 2026, 7:24 PM
Updated: Mar 5, 2026, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.7
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.