Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27148

34
FAUCET Score

CVE-2026-27148 describes a WebSocket hijacking vulnerability in Storybook's development server, affecting versions prior to 7.6.23, 8.6.17, 9.1.19, and 10.2.10. This high-severity vulnerability (CVSS 8.9) allows unauthenticated attackers to send malicious WebSocket messages due to a lack of origin validation, leading to persistent Cross-Site Scripting (XSS) or Remote Code Execution (RCE) via unsanitized input in the componentFilePath field. Exploitation typically requires a developer to visit a malicious website while their local Storybook dev server is running, though public exposure of the server increases risk. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, with minimal community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.6.23CPE matchmatch criteria
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
>= 8.1.0, < 8.6.17CPE matchmatch criteria
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
>= 9.0.0, < 9.1.19CPE matchmatch criteria
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
>= 10.0.0, < 10.2.10CPE matchmatch criteria
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.9HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 47th percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

npmpatch availablevia ghsa
Product: storybookFixed in: 8.6.17
npmpatch availablevia ghsa
Product: storybookFixed in: 9.1.19
npmpatch availablevia ghsa
Product: storybookFixed in: 10.2.10

Vendor Advisories (1)

npmGHSA-mjf5-7g4m-gx5whigh

Storybook Dev Server is Vulnerable to WebSocket Hijacking

Feb 26, 2026

References

access.redhat.com / security/cve/CVE-2026-27148
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27148.json
github.com / storybookjs/storybook/commit/0affdf928bd6fafbadfb1dfe22ce6104805e10e8
Patch
github.com / storybookjs/storybook/commit/54689a8add18ea75d628c540f4bc677592a1e685
Patch
github.com / storybookjs/storybook/commit/b8cfa77c73940c140acdcd8a06ab1ea913c44761
Patch
github.com / storybookjs/storybook/commit/d34085f39c647f5c23c3a3b2d197c18602fcf876
Patch
github.com / storybookjs/storybook/releases/tag/v10.2.10
Release Notes
github.com / storybookjs/storybook/releases/tag/v7.6.23
Release Notes
github.com / storybookjs/storybook/releases/tag/v8.6.17
Release Notes
github.com / storybookjs/storybook/releases/tag/v9.1.19
Release Notes
github.com / storybookjs/storybook/security/advisories/GHSA-mjf5-7g4m-gx5w
Vendor Advisory