Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 57%

CVE-2026-27148: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in storybookjs storybook

0
High
VulnerabilityCVE-2026-27148cvecve-2026-27148cwe-74cwe-79
Published: 02/25/2026 (02/25/2026, 21:46:48 UTC)
Source: CVE Database V5
Vendor/Project: storybookjs
Product: storybook

Description

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can silently send WebSocket messages to the local instance without any further user interaction. If the Storybook dev server is intentionally exposed publicly (e.g. for design reviews or stakeholder demos) the risk is higher, as no malicious site visit is required. Any unauthenticated attacker can send WebSocket messages to it directly. The vulnerability affects the WebSocket message handlers for creating and saving stories. Both are vulnerable to injection via unsanitized input in the componentFilePath field, which can be exploited to achieve persistent XSS or Remote Code Execution (RCE). Versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 contain a fix for the issue.

CVSS v4.0

Score 8.9high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
Active
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
High
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected software

storybook
pkg:npm/storybook
Affected versions
<7.6.23

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 08:43:27 UTC

Technical Analysis

CVE-2026-27148 describes a WebSocket hijacking vulnerability in the Storybook dev server prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10. The WebSocket connection does not validate the origin of incoming connections, allowing malicious websites or unauthenticated attackers (if the dev server is publicly exposed) to send WebSocket messages to the local Storybook instance. The vulnerability specifically affects the message handlers responsible for creating and saving stories, where unsanitized input in the componentFilePath field can be exploited for injection attacks, including persistent XSS and remote code execution. The issue is resolved in the specified fixed versions. The vulnerability does not impact production builds of Storybook.

Potential Impact

An attacker can hijack the WebSocket connection of the Storybook dev server to send malicious messages without origin validation. This can lead to injection attacks via unsanitized input, resulting in persistent cross-site scripting or remote code execution. The risk is higher if the dev server is publicly exposed, as no user interaction is required for exploitation. Production builds are not affected, limiting the impact to development environments.

Mitigation Recommendations

Fixed versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 of Storybook contain patches addressing this vulnerability. Users should upgrade to these or later versions to remediate the issue. If upgrading is not immediately possible, avoid exposing the Storybook dev server publicly and be cautious about visiting untrusted websites while the dev server is running locally. Patch status is confirmed by vendor advisories.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-02-18T00:18:53.961Z
Cvss Version
4.0
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-27148","vendor":"Red Hat"}]

Threat ID: 699f7012b7ef31ef0b5b7bb1

Added to database: 02/25/2026, 21:56:34 UTC

Last enriched: 07/15/2026, 08:43:27 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 171

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses