An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
https://github.com/dillonkirsch/CVE-2026-26720-Twenty-RCE
https://dillonkirsch.com/post/locally_hosted_twenty_rce_cve_2026_26720/