๐Ÿ” CVE Alert

CVE-2026-105220

HIGH 7.8

Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.

CWE CWE-79
Vendor klembot
Product twinejs
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for klembot twinejs

Be the first to know when new high vulnerabilities affecting klembot twinejs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

klembot / twinejs
0 โ‰ค 2.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/klembot/twinejs/issues/1706 github.com: https://github.com/klembot/twinejs github.com: https://github.com/klembot/twinejs/blob/2.12.0/src/util/import.ts#L134-L136 github.com: https://github.com/klembot/twinejs/blob/2.12.0/src/electron/main-process/scratch-file.ts#L57-L63 github.com: https://github.com/klembot/twinejs/commit/8e8a2bef5b1e20c58b99d22a2a4d8d867fb421cb github.com: https://github.com/klembot/twinejs/commit/3a9af28cabe9684730beb8b578132cad9bb5bc60 vulncheck.com: https://www.vulncheck.com/advisories/twine-2-desktop-through-2.12.0-arbitrary-code-execution-via-imported-story-files

Credits

Siyang Wu