CVE-2026-82274 | twentyhq Twenty up to 2.35.0 OAuth Callback OAuthPropagatorController.propagateOAuthCallback state redirect
A vulnerability, which was classified as problematic, has been found in twentyhq Twenty up to 2.35.0. The impacted element is the function OAuthPropagatorController.propagateOAuthCallback of the component OAuth Callback Handler. The manipulation of the argument state leads to open redirect.
This vulnerability is uniquely identified as CVE-2026-82274. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More