Review reviewHigh

CVE-2026-27148

storybookjs storybook, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can si...

CVSS
8.9
EPSS
0.54%
42.5% percentile
CISA KEV
Not listed
Published
2026.02.26
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.54%
Technical severityCVSS 8.9

Vulnerability overview

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can si...

Affected product and versions

Product
storybookjs storybook, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9
Affected versions
>= < 7.6.23, >= >= 8.1.0, < 8.6.17, >= >= 9.0.0, < 9.1.19, >= >= 10.0.0, < 10.2.10, < 7.6.23, >= 8.1.0 < 8.6.17, >= 9.0.0 < 9.1.19, >= 10.0.0 < 10.2.10
Fixed versions
7.6.23, 8.6.17, 9.1.19, 10.2.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that storybookjs storybook, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-346, CWE-74, CWE-79