Cross-Site Scripting Vulnerability in Twine 2 Desktop by Klembot
CVE-2026-105220

8.5HIGH

Key Information:

Vendor

Klembot

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105220?

Twine 2 Desktop versions up to 2.12.0 are susceptible to a cross-site scripting vulnerability that arises in the importStories() function. This flaw allows attackers to craft malicious story files that, when imported, execute arbitrary JavaScript code within the editor window. By leveraging the twineElectron openWithScratchFile IPC bridge, an attacker can cause a .bat file to be created and executed on the user’s system, potentially enabling unauthorized code execution. This poses significant risks for users who interact with untrusted or compromised story files.

Affected Version(s)

twinejs 0 <= 2.12.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.