Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the Twenty CRM platform could expose plaintext passwords for external services, such as email and calendars. If exploited, a user with standard access could view or misuse the credentials of other users, potentially leading to unauthorized access to mail and calendar data, and even the ability to reset third-party accounts. This issue affects versions prior to 2.7.0.
- Plaintext passwords for external services were exposed.
- Normal users could access other users' mail and calendar data.
- Confirm Twenty CRM relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker with standard access within a workspace can potentially steal the external service credentials of other workspace members. This occurs because the platform's GraphQL endpoint for connected accounts improperly exposes sensitive information, such as IMAP, SMTP, and CalDAV passwords, without verifying the user's identity or visibility permissions. If successful, an attacker could gain unauthorized access to linked email and calendar services, and possibly take control of those third-party accounts.
- Requires standard workspace access.
- Triggered by querying connected account metadata.
- Risk of credential theft and account compromise.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a normal workspace member could access other members' external-service credentials, including plaintext IMAP, SMTP, and CalDAV passwords. This exposure could enable unauthorized access to mail or calendars and potentially lead to the resetting of third-party accounts. Google and Microsoft OAuth-only workspaces are not affected.
- Plaintext external-service credentials.
- Unauthorized GraphQL query execution.
- Compromised mail and calendar access.
Operational Fix
Recommended remediation, mitigation, and detection steps
Technical leaders and system owners should prioritize identifying all Twenty instances within their environment. Since this vulnerability exposes sensitive credentials through a GraphQL query accessible to any workspace member, the immediate first step is to confirm if the affected instances are externally reachable and if they host business-critical data. Once identified and validated, engage the platform or application owners to verify the scope of exposure and plan remediation, which may involve coordinating with vendors if custom integrations are in place or if direct patching is not feasible.
- Platform or application owners must address.
- Verify external reachability and criticality.
- Plan targeted remediation or mitigation.