CVE-2026-55583: Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor'...
Added to the CISA Known Exploited Vulnerabilities catalog on 24 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.6.
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor's AgentTurnResolver, in packages/twenty-server/src/engine/metadata-modules/ai/ai-agent-monitor/reso ...
Required action: Review and patch if applicable to your AI infrastructure.