CVE-2026-27148
storybookjs storybook, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9
Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted. Exploitation requires a developer to visit a malicious website while their local Storybook dev server is running. Because the WebSocket connection does not validate the origin of incoming connections, a malicious site can si...
- CVSS
- 8.9
- EPSS
- 0.54% 42.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.26