CVE-2026-55583 Details
Description
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor's AgentTurnResolver, in packages/twenty-server/src/engine/metadata-modules/ai/ai-agent-monitor/reso lvers/agent-turn.resolver.ts. The agentTurns(agentId) query and the evaluateAgentTurn(turnId) mutation looked up rows by agentId or id only; although AgentTurnEntity has a workspaceId column, it was not included in the WHERE clause, and the class-level guards only checked that the caller was authenticated in some workspace rather than that the requested object belonged to it, with the same flaw present in agent-turn-grader.service.ts. As a result, any authenticated user with the AI settings flag, a workspace owner by default, could target any other workspace on the same instance given the victim's agentId or turnId: agentTurns returned the victim's full chat history including message parts such as raw chat text, tool calls, and tool outputs, while evaluateAgentTurn inserted an agentTurnEvaluation row with the victim's workspaceId and fed the victim's turn into the default LLM. The agentId and turnId are non-guessable UUIDs but are exposed in the URL of the settings page. This issue is fixed in version 2.9.0.
A cross-workspace insecure direct object reference (IDOR) vulnerability has been identified in the Twenty CRM platform, prior to version 2.9.0. The issue resides in the AI agent monitor's AgentTurnResolver, where the agentTurns and evaluateAgentTurn functions fail to properly validate workspace ownership. Although the AgentTurnEntity includes a workspaceId column, it is not utilized in the query's WHERE clause. This oversight allows any authenticated user with the AI settings flag, typically a workspace owner, to access or manipulate data from other workspaces on the same instance, using the agentId or turnId of a victim. The vulnerability is further exacerbated by the fact that these IDs, while non-guessable UUIDs, are exposed in the URL of the settings page.
Users are advised to update to Twenty CRM version 2.9.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/twentyhq/twenty/security/advisories/GHSA-v39r-w5vg-j9pp | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/twentyhq/twenty/security/advisories/GHSA-v39r-w5vg-j9pp | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Twenty | < 2.9.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion