Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. storybook
  4. ›
  5. CVE-2026-27148

CVE-2026-27148: Storybook Dev Server is Vulnerable to WebSocket Hijacking

February 26, 2026

The WebSocket functionality in Storybook’s dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability only affects the Storybook dev server; production builds are not impacted.

References

  • github.com/advisories/GHSA-mjf5-7g4m-gx5w
  • github.com/storybookjs/storybook
  • github.com/storybookjs/storybook/commit/0affdf928bd6fafbadfb1dfe22ce6104805e10e8
  • github.com/storybookjs/storybook/commit/54689a8add18ea75d628c540f4bc677592a1e685
  • github.com/storybookjs/storybook/commit/b8cfa77c73940c140acdcd8a06ab1ea913c44761
  • github.com/storybookjs/storybook/commit/d34085f39c647f5c23c3a3b2d197c18602fcf876
  • github.com/storybookjs/storybook/releases/tag/v10.2.10
  • github.com/storybookjs/storybook/releases/tag/v7.6.23
  • github.com/storybookjs/storybook/releases/tag/v8.6.17
  • github.com/storybookjs/storybook/releases/tag/v9.1.19
  • github.com/storybookjs/storybook/security/advisories/GHSA-mjf5-7g4m-gx5w
  • nvd.nist.gov/vuln/detail/CVE-2026-27148

Code Behaviors & Features

Detect and mitigate CVE-2026-27148 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 8.1.0 before 8.6.17, all versions starting from 8.7.0-alpha.0 before 9.1.19, all versions starting from 10.0.0-beta.0 before 10.2.10

Fixed versions

  • 8.6.17
  • 9.1.19
  • 10.2.10

Solution

Upgrade to versions 10.2.10, 8.6.17, 9.1.19 or above.

Impact 9.6 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-1385: Missing Origin Validation in WebSockets
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

npm/storybook/CVE-2026-27148.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:18:02 +0000.