Vendor
Twine 2 desktop versions through 2.12.0 contain a cross-site scripting flaw in the importStories function that can be leveraged via an IPC bridge to achieve arbitrary code execution.