PatchSiren

klembot CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH klembot CVE published 2026-10-04

CVE-2026-105220

CVE-2026-105220 is a high-severity vulnerability in Twine 2 desktop through 2.12.0 that allows for cross-site scripting (XSS) via imported story files. The vulnerability is due to the importStories() function executing markup from imported story files in the editor window. An attacker can craft a malicious story file that calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file [truncated]