CVE-2026-27148: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in storybookjs storybook
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can silently send WebSocket messages to the local instance without any further user interaction. If the Storybook dev server is intentionally exposed publicly (e.g. for design reviews or stakeholder demos) the risk is higher, as no malicious site visit is required. Any unauthenticated attacker can send WebSocket messages to it directly. The vulnerability affects the WebSocket message handlers for creating and saving stories. Both are vulnerable to injection via unsanitized input in the componentFilePath field, which can be exploited to achieve persistent XSS or Remote Code Execution (RCE). Versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 contain a fix for the issue.
AI Analysis
Technical Summary
CVE-2026-27148 describes a WebSocket hijacking vulnerability in the Storybook dev server prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10. The WebSocket connection does not validate the origin of incoming connections, allowing malicious websites or unauthenticated attackers (if the dev server is publicly exposed) to send WebSocket messages to the local Storybook instance. The vulnerability specifically affects the message handlers responsible for creating and saving stories, where unsanitized input in the componentFilePath field can be exploited for injection attacks, including persistent XSS and remote code execution. The issue is resolved in the specified fixed versions. The vulnerability does not impact production builds of Storybook.
Potential Impact
An attacker can hijack the WebSocket connection of the Storybook dev server to send malicious messages without origin validation. This can lead to injection attacks via unsanitized input, resulting in persistent cross-site scripting or remote code execution. The risk is higher if the dev server is publicly exposed, as no user interaction is required for exploitation. Production builds are not affected, limiting the impact to development environments.
Mitigation Recommendations
Fixed versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 of Storybook contain patches addressing this vulnerability. Users should upgrade to these or later versions to remediate the issue. If upgrading is not immediately possible, avoid exposing the Storybook dev server publicly and be cautious about visiting untrusted websites while the dev server is running locally. Patch status is confirmed by vendor advisories.
CVE-2026-27148: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in storybookjs storybook
Description
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can silently send WebSocket messages to the local instance without any further user interaction. If the Storybook dev server is intentionally exposed publicly (e.g. for design reviews or stakeholder demos) the risk is higher, as no malicious site visit is required. Any unauthenticated attacker can send WebSocket messages to it directly. The vulnerability affects the WebSocket message handlers for creating and saving stories. Both are vulnerable to injection via unsanitized input in the componentFilePath field, which can be exploited to achieve persistent XSS or Remote Code Execution (RCE). Versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 contain a fix for the issue.
CVSS v4.0
Score 8.9high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-27148 describes a WebSocket hijacking vulnerability in the Storybook dev server prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10. The WebSocket connection does not validate the origin of incoming connections, allowing malicious websites or unauthenticated attackers (if the dev server is publicly exposed) to send WebSocket messages to the local Storybook instance. The vulnerability specifically affects the message handlers responsible for creating and saving stories, where unsanitized input in the componentFilePath field can be exploited for injection attacks, including persistent XSS and remote code execution. The issue is resolved in the specified fixed versions. The vulnerability does not impact production builds of Storybook.
Potential Impact
An attacker can hijack the WebSocket connection of the Storybook dev server to send malicious messages without origin validation. This can lead to injection attacks via unsanitized input, resulting in persistent cross-site scripting or remote code execution. The risk is higher if the dev server is publicly exposed, as no user interaction is required for exploitation. Production builds are not affected, limiting the impact to development environments.
Mitigation Recommendations
Fixed versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 of Storybook contain patches addressing this vulnerability. Users should upgrade to these or later versions to remediate the issue. If upgrading is not immediately possible, avoid exposing the Storybook dev server publicly and be cautious about visiting untrusted websites while the dev server is running locally. Patch status is confirmed by vendor advisories.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-02-18T00:18:53.961Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-27148","vendor":"Red Hat"}]
Threat ID: 699f7012b7ef31ef0b5b7bb1
Added to database: 02/25/2026, 21:56:34 UTC
Last enriched: 07/15/2026, 08:43:27 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 171
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.