CVE-2026-27148Disclosure(storybook / storybook)

LOWCVSS 9.6 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can silently send WebSocket messages to the local instance without any further user interaction. If the Storybook dev server is intentionally exposed publicly (e.g. for design reviews or stakeholder demos) the risk is higher, as no malicious site visit is required. Any unauthenticated attacker can send WebSocket messages to it directly. The vulnerability affects the WebSocket message handlers for creating and saving stories. Both are vulnerable to injection via unsanitized input in the componentFilePath field, which can be exploited to achieve persistent XSS or Remote Code Execution (RCE). Versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10 contain a fix for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-79CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • storybook

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
storybook

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-26: 4Technical Details · 2026-02-26: 202-26
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27148 Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket f… https://www.cve.org/CVERecord?id=CVE-2026-27148

    Post summary

    The text briefly references CVE-2026-27148, noting affected Storybook versions but provides no further details on exploitation, patches, or technical specifics.

    00010559
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27148: Storybook Ending: Dev Server RCE via WebSocket Hijacking A critical flaw in the Storybook development server allows attackers to hijack the WebSocket connection from a malicious website via Cross-Site WebSocket Hijacking (CSWSH). Becau... https://cvereports.com/reports/CVE-2026-27148

    Post summary

    A critical flaw in Storybook’s development server permits attackers to hijack WebSocket connections via CSWSH, potentially enabling remote code execution.

    0000015
    32 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-27148 Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket f… https://www.cve.org/CVERecord?id=CVE-2026-27148 ----- Traducción: CVE-2026-27148 Sto… http://infoflow.cloud`

    Post summary

    The post merely cites CVE‑2026‑27148 and links to its CVE record, offering no further technical or actionable information.

    0000027
    54 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27148 WebSocket Hijacking Vulnerability in Storybook Dev Server Versions Before 10.2.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27148

    Post summary

    A WebSocket hijacking vulnerability (CVE-2026-27148) affects Storybook Dev Server versions prior to 10.2.10.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstorybookstorybook-node.js-

Explore more