CVE-2026-82274 UNKNOWN

CVE-2026-82274

Published: 2026-08-28

Description

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect users to arbitrary hosts while forwarding OAuth authorization codes, bypassing domain validation when IS_MULTIWORKSPACE_ENABLED is disabled.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…