Cross-Site Scripting Vulnerability in Twine 2 Desktop by Klembot
CVE-2026-105220
8.5HIGH
What is CVE-2026-105220?
Twine 2 Desktop versions up to 2.12.0 are susceptible to a cross-site scripting vulnerability that arises in the importStories() function. This flaw allows attackers to craft malicious story files that, when imported, execute arbitrary JavaScript code within the editor window. By leveraging the twineElectron openWithScratchFile IPC bridge, an attacker can cause a .bat file to be created and executed on the user’s system, potentially enabling unauthorized code execution. This poses significant risks for users who interact with untrusted or compromised story files.
Affected Version(s)
twinejs 0 <= 2.12.0
