Twine 2 Cross-Site Scripting to Remote Code Execution
Twine 2 desktop versions through 2.12.0 contain a cross-site scripting flaw in the importStories function that can be leveraged via an IPC bridge to achieve arbitrary code execution.
CVE search metadata
CVE search record: CVE-2026-105220. Severity: high. CVSS: 7.8. KEV: no. Product: Twine (<= 2.12.0). Brief: Twine 2 Cross-Site Scripting to Remote Code Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-twine-xss-rce/
Twine 2 desktop application versions up to 2.12.0 are vulnerable to a cross-site scripting (XSS) vulnerability within the importStories() function. An attacker can craft a malicious story file containing embedded JavaScript that, when imported into the editor, executes within the application context. This vulnerability is escalated through the misuse of the 'twineElectron' IPC bridge, specifically the 'openWithScratchFile' method. By manipulating this bridge, an attacker can force the application to write and subsequently execute an arbitrary .bat file on the host operating system. This allows for code execution under the privileges of the user running the Twine desktop application. This flaw poses a significant risk to users who import untrusted story files from external sources, as the malicious code triggers upon file processing within the editor environment.
Impact
Successful exploitation allows for arbitrary code execution on the user's machine. This can lead to full compromise of the user account, potentially resulting in data theft, persistence establishment, or lateral movement within the network. Users of the Twine desktop application who frequently collaborate or import content from community repositories are at the highest risk of being targeted via malicious story files.
Recommendation
Prioritized actions for security teams to address CVE-2026-105220:
- Upgrade the Twine desktop application to a version beyond 2.12.0 immediately as it becomes available to patch the importStories() XSS vulnerability.
- Implement an organizational policy to restrict the importing of story files from untrusted or public third-party repositories until the application is patched.
- Use endpoint monitoring to detect unusual process lineage where the Twine application process (Twine.exe) spawns cmd.exe or batch file executors.
Immediate actions
Deploy process monitoring rule to detect Twine spawning cmd.exe
Mitigations
Restrict importing untrusted story files
CVE-2026-105220
Detection coverage 1
Detect Suspicious Twine Process Spawning Command Interpreter
highDetects the Twine desktop application spawning a command interpreter, which may indicate the execution of a malicious .bat file via the openWithScratchFile IPC bridge.
Detection queries are available on the platform. Get full rules →