Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user. | |
| Title | Twine 2 Desktop through 2.12.0 Arbitrary Code Execution via Imported Story Files | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T22:31:46.420Z
Reserved: 2026-10-04T13:04:00.479Z
Link: CVE-2026-105220
No data.
No data.
No data.
OpenCVE Enrichment
No data.