Description
Summary
A critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM v1.7.7 through v1.16.7 via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute arbitrary OS commands on the database server by injecting SQL through the unsanitized timeZone parameter in the REST API groupBy endpoint.
Details
The vulnerability consists of two chained weaknesses:
1. SQL Injection (CWE-89)
File: packages/twenty-server/src/engine/api/graphql/graphql-query-runner/group-by/resolvers/utils/get-group-by-expression.util.ts
const timeZoneAsDateTruncParameter = shouldUseTimeZone
? `, '${groupByField.timeZone}'` // Direct interpolation — no sanitization
: '';
const timeZoneAsToCharParameter = shouldUseTimeZone
? ` AT TIME ZONE '${groupByField.timeZone}'` // Direct interpolation — no sanitization
: '';
The timeZone field within the group_by query parameter is directly interpolated into a raw SQL expression using JavaScript template literals without any parameterization, validation, or escaping. This produces:
TO_CHAR(DATE_TRUNC('DAY', "company"."createdAt", '<TIMEZONE>') AT TIME ZONE '<TIMEZONE>', 'YYYY-MM-DD')
An attacker can break out of the SQL string context and execute arbitrary SQL including stacked queries.
2. Remote Code Execution via COPY TO PROGRAM (CWE-78)
Twenty CRM's default Docker deployment runs PostgreSQL as a superuser (not the cloud version). This allows an attacker to:
- Create a PostgreSQL large object containing a shell script via
lo_from_bytea()
- Export it to the filesystem via
lo_export()
- Execute it via a stacked
COPY (SELECT 1) TO PROGRAM query
Impact
Who is Impacted
- All Twenty CRM installations from v1.7.7 through v1.16.7
- Organization running Twenty CRM with its default Docker deployment (superuser PostgreSQL)
- No administrator role required
Description
Summary
A critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM v1.7.7 through v1.16.7 via a chained SQL Injection and PostgreSQL
COPY TO PROGRAMattack. If Postgres user is a super user then any authenticated user can execute arbitrary OS commands on the database server by injecting SQL through the unsanitizedtimeZoneparameter in the REST APIgroupByendpoint.Details
The vulnerability consists of two chained weaknesses:
1. SQL Injection (CWE-89)
File:
packages/twenty-server/src/engine/api/graphql/graphql-query-runner/group-by/resolvers/utils/get-group-by-expression.util.tsThe
timeZonefield within thegroup_byquery parameter is directly interpolated into a raw SQL expression using JavaScript template literals without any parameterization, validation, or escaping. This produces:An attacker can break out of the SQL string context and execute arbitrary SQL including stacked queries.
2. Remote Code Execution via COPY TO PROGRAM (CWE-78)
Twenty CRM's default Docker deployment runs PostgreSQL as a superuser (not the cloud version). This allows an attacker to:
lo_from_bytea()lo_export()COPY (SELECT 1) TO PROGRAMqueryImpact
Who is Impacted