CVE-2026-27148 describes a WebSocket hijacking vulnerability in Storybook's development server, affecting versions prior to 7.6.23, 8.6.17, 9.1.19, and 10.2.10. This high-severity vulnerability (CVSS 8.9) allows unauthenticated attackers to send malicious WebSocket messages due to a lack of origin validation, leading to persistent Cross-Site Scripting (XSS) or Remote Code Execution (RCE) via unsanitized input in the componentFilePath field. Exploitation typically requires a developer to visit a malicious website while their local Storybook dev server is running, though public exposure of the server increases risk. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, with minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.6.23CPE matchmatch criteria | cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:* | ||
>= 8.1.0, < 8.6.17CPE matchmatch criteria | cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:* | ||
>= 9.0.0, < 9.1.19CPE matchmatch criteria | cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:* | ||
>= 10.0.0, < 10.2.10CPE matchmatch criteria | cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.