CVE-2026-44729 | twentyhq twenty up to 1.18.0 File Serving Endpoint /files/ cross site scripting (GHSA-f5h2-3qw5-3qp7 / EUVD-2026-31895)
A vulnerability described as problematic has been identified in twentyhq twenty up to 1.18.0. Affected by this vulnerability is an unknown functionality of the file /files/ of the component File Serving Endpoint. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-44729. The attack can be executed remotely. There is not any exploit available.