HIGH
klembot
CVE published 2026-10-04
CVE-2026-105220
CVE-2026-105220 is a high-severity vulnerability in Twine 2 desktop through 2.12.0 that allows for cross-site scripting (XSS) via imported story files. The vulnerability is due to the importStories() function executing markup from imported story files in the editor window. An attacker can craft a malicious story file that calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file [truncated]