Skip to content
Threat Feed
high advisory

Twine 2 Cross-Site Scripting to Remote Code Execution

Twine 2 desktop versions through 2.12.0 contain a cross-site scripting flaw in the importStories function that can be leveraged via an IPC bridge to achieve arbitrary code execution.

CVE search metadata

CVE search record: CVE-2026-105220. Severity: high. CVSS: 7.8. KEV: no. Product: Twine (<= 2.12.0). Brief: Twine 2 Cross-Site Scripting to Remote Code Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-twine-xss-rce/

Twine 2 desktop application versions up to 2.12.0 are vulnerable to a cross-site scripting (XSS) vulnerability within the importStories() function. An attacker can craft a malicious story file containing embedded JavaScript that, when imported into the editor, executes within the application context. This vulnerability is escalated through the misuse of the 'twineElectron' IPC bridge, specifically the 'openWithScratchFile' method. By manipulating this bridge, an attacker can force the application to write and subsequently execute an arbitrary .bat file on the host operating system. This allows for code execution under the privileges of the user running the Twine desktop application. This flaw poses a significant risk to users who import untrusted story files from external sources, as the malicious code triggers upon file processing within the editor environment.

Impact

Successful exploitation allows for arbitrary code execution on the user's machine. This can lead to full compromise of the user account, potentially resulting in data theft, persistence establishment, or lateral movement within the network. Users of the Twine desktop application who frequently collaborate or import content from community repositories are at the highest risk of being targeted via malicious story files.

Recommendation

Prioritized actions for security teams to address CVE-2026-105220:

  • Upgrade the Twine desktop application to a version beyond 2.12.0 immediately as it becomes available to patch the importStories() XSS vulnerability.
  • Implement an organizational policy to restrict the importing of story files from untrusted or public third-party repositories until the application is patched.
  • Use endpoint monitoring to detect unusual process lineage where the Twine application process (Twine.exe) spawns cmd.exe or batch file executors.

Immediate actions

Deploy process monitoring rule to detect Twine spawning cmd.exe

Detection Engineering 24h

Mitigations

Restrict importing untrusted story files

immediate IT Operations

CVE-2026-105220

Detection coverage 1

Detect Suspicious Twine Process Spawning Command Interpreter

high

Detects the Twine desktop application spawning a command interpreter, which may indicate the execution of a malicious .bat file via the openWithScratchFile IPC bridge.

sigma tactics: execution techniques: T1059.003 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →