CVE-2026-105220: Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files
Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must provide a crafted story file and persuade a user to import it into the Twine 2 desktop editor. The malicious markup then executes in the editor window and can use the exposed IPC bridge to write and open a .bat file.
What level of access does exploitation give an attacker?
Successful exploitation can execute code as the user running Twine 2 Desktop. The listed impact includes high confidentiality, integrity, and availability impact.
Are users affected merely by opening Twine, or is interaction required?
User interaction is required: the crafted story file must be imported. The vulnerability is triggered through the importStories() handling of imported story content.