<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:twine:twine:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atwinetwine/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 00:56:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atwinetwine/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Twine 2 Cross-Site Scripting to Remote Code Execution</title><link>https://feed.craftedsignal.io/briefs/2026-10-twine-xss-rce/</link><pubDate>Mon, 05 Oct 2026 00:56:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-twine-xss-rce/</guid><description>Twine 2 desktop versions through 2.12.0 contain a cross-site scripting flaw in the importStories function that can be leveraged via an IPC bridge to achieve arbitrary code execution.</description><content:encoded><![CDATA[<p>Twine 2 desktop application versions up to 2.12.0 are vulnerable to a cross-site scripting (XSS) vulnerability within the importStories() function. An attacker can craft a malicious story file containing embedded JavaScript that, when imported into the editor, executes within the application context. This vulnerability is escalated through the misuse of the 'twineElectron' IPC bridge, specifically the 'openWithScratchFile' method. By manipulating this bridge, an attacker can force the application to write and subsequently execute an arbitrary .bat file on the host operating system. This allows for code execution under the privileges of the user running the Twine desktop application. This flaw poses a significant risk to users who import untrusted story files from external sources, as the malicious code triggers upon file processing within the editor environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution on the user's machine. This can lead to full compromise of the user account, potentially resulting in data theft, persistence establishment, or lateral movement within the network. Users of the Twine desktop application who frequently collaborate or import content from community repositories are at the highest risk of being targeted via malicious story files.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams to address CVE-2026-105220:</p>
<ul>
<li>Upgrade the Twine desktop application to a version beyond 2.12.0 immediately as it becomes available to patch the importStories() XSS vulnerability.</li>
<li>Implement an organizational policy to restrict the importing of story files from untrusted or public third-party repositories until the application is patched.</li>
<li>Use endpoint monitoring to detect unusual process lineage where the Twine application process (Twine.exe) spawns cmd.exe or batch file executors.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cross-site-scripting</category><category>rce</category><category>client-side-vulnerability</category></item></channel></rss>