{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/twine/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:twine:twine:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-105220"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Twine (\u003c= 2.12.0)"],"_cs_severities":["high"],"_cs_tags":["cross-site-scripting","rce","client-side-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Twine"],"content_html":"\u003cp\u003eTwine 2 desktop application versions up to 2.12.0 are vulnerable to a cross-site scripting (XSS) vulnerability within the importStories() function. An attacker can craft a malicious story file containing embedded JavaScript that, when imported into the editor, executes within the application context. This vulnerability is escalated through the misuse of the 'twineElectron' IPC bridge, specifically the 'openWithScratchFile' method. By manipulating this bridge, an attacker can force the application to write and subsequently execute an arbitrary .bat file on the host operating system. This allows for code execution under the privileges of the user running the Twine desktop application. This flaw poses a significant risk to users who import untrusted story files from external sources, as the malicious code triggers upon file processing within the editor environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the user's machine. This can lead to full compromise of the user account, potentially resulting in data theft, persistence establishment, or lateral movement within the network. Users of the Twine desktop application who frequently collaborate or import content from community repositories are at the highest risk of being targeted via malicious story files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams to address CVE-2026-105220:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Twine desktop application to a version beyond 2.12.0 immediately as it becomes available to patch the importStories() XSS vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement an organizational policy to restrict the importing of story files from untrusted or public third-party repositories until the application is patched.\u003c/li\u003e\n\u003cli\u003eUse endpoint monitoring to detect unusual process lineage where the Twine application process (Twine.exe) spawns cmd.exe or batch file executors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T00:56:17Z","date_published":"2026-10-05T00:56:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-twine-xss-rce/","summary":"Twine 2 desktop versions through 2.12.0 contain a cross-site scripting flaw in the importStories function that can be leveraged via an IPC bridge to achieve arbitrary code execution.","title":"Twine 2 Cross-Site Scripting to Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-10-twine-xss-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Twine","version":"https://jsonfeed.org/version/1.1"}