Storybook is a widely adopted component development and documentation framework used in web application projects, with its vulnerability profile centered on a single product that integrates with frontend build and deployment pipelines. The recurring weaknesses reflect risks inherent to a web-accessible documentation system: exposure of sensitive information through configuration or file handling, cross-site scripting, injection flaws in generated content, and accidental inclusion of secrets in built artifacts.
The number and severity of CVEs published that impact products developed by Storybook over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27148CRITICAL Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality i | Feb 25, 2026 | 9.6 | 34 | NO | NO |
CVE-2025-68429MEDIUM Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6 | Dec 17, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Storybook.
Media articles that mention a CVE ID that affects a product developed by Storybook — matched by CVE ID, not by vendor name.