Impact
Twine 2 Desktop versions up to 2.12.0 contain a cross‑site scripting flaw in the importStories function that allows a crafted story file to inject markup into the editor. The injected script can call the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, causing the operating system to execute the script with the current user’s privileges. This results in arbitrary code execution as the user, exposing the system to full compromise.
Affected Systems
The affected product is Twine 2 Desktop, distributed by klembot (twinejs). Versions 2.12.0 and earlier are vulnerable; any installation of Twine 2 Desktop that has not been upgraded past 2.12.0 is at risk.
Risk and Exploitability
The CVSS score of 8.5 marks this flaw as high severity. Exploitation requires an attacker to supply a malicious story file to a user who opens it; therefore, the attack vector is local and depends on user action. EPSS data is not available, so the overall exploitation probability is unknown, but the lack of a KEV listing suggests an unreported or low‑profile risk at the time of analysis.
OpenCVE Enrichment