Description
Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.
Published: 2026-10-04
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Twine 2 Desktop versions up to 2.12.0 contain a cross‑site scripting flaw in the importStories function that allows a crafted story file to inject markup into the editor. The injected script can call the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, causing the operating system to execute the script with the current user’s privileges. This results in arbitrary code execution as the user, exposing the system to full compromise.

Affected Systems

The affected product is Twine 2 Desktop, distributed by klembot (twinejs). Versions 2.12.0 and earlier are vulnerable; any installation of Twine 2 Desktop that has not been upgraded past 2.12.0 is at risk.

Risk and Exploitability

The CVSS score of 8.5 marks this flaw as high severity. Exploitation requires an attacker to supply a malicious story file to a user who opens it; therefore, the attack vector is local and depends on user action. EPSS data is not available, so the overall exploitation probability is unknown, but the lack of a KEV listing suggests an unreported or low‑profile risk at the time of analysis.

Generated by OpenCVE AI on October 4, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Twine to a version newer than 2.12.0, which removes the vulnerable importStories behaviour.
  • Avoid opening story files from untrusted or unknown sources, and inspect or sanitize files before import.
  • If possible, disable or remove the twineElectron openWithScratchFile IPC bridge so that imported scripts cannot write executable files.

Generated by OpenCVE AI on October 4, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Description Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.
Title Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T22:31:46.420Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105220

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T23:16:59.627

Modified: 2026-10-04T23:16:59.627

Link: CVE-2026-105220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T23:30:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')