Sceawere

Vulnerability Detail

CVE-2026-105220UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Twine 2 Desktop XSS RCE

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
19h ago
Vendor
klembot
Product
twinejs
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-04T23:16:59.627Z",
  "pubdate": "2026-10-04T23:16:59.627Z",
  "executiveSummary": "Twine 2 desktop versions through 2.12.0 contain a critical security vulnerability involving improper handling of untrusted input during the story import process. The flaw originates in the importStories() function, which fails to adequately sanitize markup from imported story files, leading to a Cross-Site Scripting (XSS) condition within the application's editor environment.\nThis vulnerability is particularly severe because the application leverages the twineElectron openWithScratchFile IPC bridge. By exploiting the XSS vector, an attacker can transition from arbitrary script execution within the editor window to unauthorized system-level operations. Specifically, an attacker can craft a malicious story file designed to interface with the IPC bridge to write and execute a .bat file on the underlying operating system.\nThe successful exploitation of this vulnerability results in Remote Code Execution (RCE) with the privileges of the user running the Twine 2 application. This poses a significant risk to confidentiality, integrity, and availability, as an attacker can execute arbitrary commands, install malware, or exfiltrate sensitive data. No authentication is required to trigger the exploit, as it relies on the user importing a weaponized file into the affected software.",
  "technicalDetails": "The vulnerability resides within the Twine 2 desktop import mechanism, specifically inside the importStories() function. This function is responsible for parsing and rendering story files imported by the user into the editor window. Due to insufficient input validation and sanitization, the editor processes embedded HTML and JavaScript contained within these story files as trusted content, facilitating a Cross-Site Scripting (XSS) exploit.\nThe exploit flow leverages the application's integration with Electron's Inter-Process Communication (IPC) architecture. Twine 2 utilizes the twineElectron openWithScratchFile IPC bridge to manage project files and temporary data. This bridge is intended to facilitate file operations but acts as an escalation vector when exposed to the renderer process via XSS.\nStep-by-step exploitation occurs as follows: First, an attacker constructs a maliciously crafted story file containing a payload designed to execute JavaScript within the Twine 2 editor window. Upon importing the file, the importStories() function parses the markup, allowing the attacker's script to execute in the context of the application's renderer process. Second, once code execution is achieved in the renderer, the script interacts with the exposed twineElectron IPC bridge. Third, the script invokes the openWithScratchFile method, passing specifically crafted parameters that instruct the bridge to write a .bat file to the host file system. Finally, the script triggers the execution of the newly created .bat file, resulting in arbitrary code execution on the host machine.\nThe impact of this vulnerability is critical because it bridges the gap between a client-side scripting flaw and full system compromise. Because the Electron renderer process maintains access to these privileged IPC bridges, the XSS effectively bypasses the standard browser-based security sandbox. The attacker gains the capability to execute commands under the user's current session security context. Given that this is a local desktop application, the threat is primarily focused on systems where users may import third-party story files from untrusted sources, effectively weaponizing the primary file import feature for binary execution."
}
CVE-2026-105220: Twine 2 Desktop XSS RCE (HIGH Severity, CVSS: 7.8) | Sceawere