Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.
https://github.com/klembot/twinejs/issues/1706
https://github.com/klembot/twinejs/commit/8e8a2bef5b1e20c58b99d22a2a4d8d867fb421cb
https://github.com/klembot/twinejs/commit/3a9af28cabe9684730beb8b578132cad9bb5bc60
https://github.com/klembot/twinejs/blob/2.12.0/src/util/import.ts#L134-L136
https://github.com/klembot/twinejs/blob/2.12.0/src/electron/main-process/scratch-file.ts#L57-L63
Published: 2026-10-04
Updated: 2026-10-05
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.5
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.00151