Storybook Security Advisory: What Developers Need to Know
Two Storybook advisories cover different risks: secrets in published builds and WebSocket hijacking in the development server. Check exposure and patch the right branch.
Storybook has two separate security advisories developers should check: CVE-2025-68429, about sensitive values from .env files ending up in published Storybook builds under specific conditions, and CVE-2026-27148, about WebSocket hijacking in the development server. The fixes differ by release branch. Identify your version, inspect whether the relevant exposure conditions apply, upgrade to a release that fixes both issues for your branch, and rotate secrets that may have been published.
At a glance
| Advisory | Affected component | Exposure condition | Main response |
|---|---|---|---|
| CVE-2025-68429 | Published Storybook build | Storybook 7.0.0 or later, a .env file containing secrets present at build time, and the resulting build published to the web |
Inspect published bundles, rotate potentially exposed secrets, and upgrade |
| CVE-2026-27148 | Storybook development server | A developer visits a malicious website while a vulnerable local server is running, or the server is exposed publicly | Upgrade and review whether the dev server is reachable from the internet |
The first issue does not affect storybook dev, deployed applications that share the repository, or Storybook 6 and earlier, according to its advisory. The second affects the dev server; production builds are not affected by that issue.
1. CVE-2025-68429: secrets in published builds
Storybook’s December 17, 2025 advisory describes a case where variables defined in a .env file could be included in output from storybook build. If that output is published, a visitor can inspect its client-side files and discover bundled values. Anything included in a browser-delivered bundle must be treated as public, even if the source value was stored in a private file before the build.
When the advisory says a project is exposed
- Storybook is version 7.0.0 or later.
- The build runs in a directory containing a
.envfile, including variants such as.env.local. - The file contains sensitive secrets.
- The generated Storybook build is published to the web.
The advisory says builds made without a .env file at build time are not affected, including common CI builds where secrets are supplied through the CI platform environment. It also says storybook dev and deployed applications sharing the repository are not affected by this issue.
Fixed releases for the .env issue
| Release branch | First version listed as fixed |
|---|---|
| 7.x | 7.6.21 |
| 8.x | 8.6.15 |
| 9.x | 9.1.17 |
| 10.x | 10.1.10 |
These are the fixes for this advisory alone. The later WebSocket advisory has higher minimum fixed versions on the branches shown below, so use the later version when addressing both.
2. CVE-2026-27148: development-server WebSocket hijacking
The February 25, 2026 GitHub advisory says Storybook’s dev server WebSocket functionality did not validate the origin of incoming connections. Exploitation can occur when a developer visits a malicious website while a vulnerable local Storybook dev server is running: the site can send WebSocket messages to the local instance without further interaction. If a dev server is intentionally exposed publicly, an attacker may connect directly, which increases the risk.
The advisory rates the issue High, with a CVSS score of 8.9. It says the vulnerable functionality was introduced in 8.1, while the fix was also applied to 7.x as a precaution. Production builds are not affected by this issue.
Fixed releases for the WebSocket issue
| Release branch | First version listed as fixed |
|---|---|
| 7.x | 7.6.23 |
| 8.x | 8.6.17 |
| 9.x | 9.1.19 |
| 10.x | 10.2.10 |
For a branch listed in both advisories, these WebSocket fix versions are later than the .env fix versions. Upgrading to at least the WebSocket fixed version therefore covers the two listed issues on that branch. Confirm the version remains supported and check the current official advisory before upgrading, since security releases can change.
3. Check your project and choose a safe version
- Find the installed version. Check the package manifest and lockfile for the Storybook packages used in the project. Include developer machines, CI jobs, and any separate workspace or package that runs Storybook.
- Identify the release branch. Match the installed version to 7.x, 8.x, 9.x, or 10.x. Do not compare only the major version; the patched minimum is branch-specific.
- Check the build inputs for CVE-2025-68429. Determine whether a
.env,.env.local, or other environment file was present in the working directory when a published Storybook build ran, and whether it contained secrets. - Check dev-server exposure for CVE-2026-27148. Note whether developers run Storybook locally while browsing untrusted sites and whether any development server is intentionally reachable from the public internet.
- Upgrade Storybook. Use at least the fixed release for the relevant branch in the WebSocket table to address both advisories listed here. Upgrade local installations and CI before publishing another build.
- Audit and rotate credentials if needed. If a potentially affected build was published with secrets from a
.envfile, treat those secrets as compromised. Revoke or rotate them, check their access logs where available, and remove the secret values from future client-side build inputs.
Branch-by-branch patch choice for both advisories
| Branch | .env issue fixed from | WebSocket issue fixed from | Minimum shown here for both |
|---|---|---|---|
| 7.x | 7.6.21 | 7.6.23 | 7.6.23 |
| 8.x | 8.6.15 | 8.6.17 | 8.6.17 |
| 9.x | 9.1.17 | 9.1.19 | 9.1.19 |
| 10.x | 10.1.10 | 10.2.10 | 10.2.10 |
This table reports the versions in the supplied advisories, not a guarantee that a branch is currently supported or that these are the latest releases. Storybook’s security policy says vulnerabilities are addressed on the latest major version; the previous two majors receive backports for High or Critical issues, while older versions are unsupported. Review the Storybook security policy and the linked advisories for current guidance.
4. Keep secrets out of browser-delivered Storybook output
Storybook notes that some projects may rely on the previous undocumented environment-variable behavior. If a non-secret value is needed in Storybook, use a STORYBOOK_ prefix or Storybook’s env configuration property. Do not place credentials, private tokens, signing keys, or other secrets in values that become part of the generated bundle. A variable name that sounds internal does not make a bundled value private.
CI environment variables can avoid the specific .env-file condition described in this advisory when no environment file is present at build time. They are not a way to make a value safe for inclusion in client-side output: if Storybook’s configuration passes that value into the bundle, it is visible to users.
5. Troubleshooting
| Symptom or question | Likely cause | What to do |
|---|---|---|
| My package says 8.6.16; am I patched for both? | That is below the listed 8.6.17 WebSocket fix. | Upgrade to at least 8.6.17 on the 8.x branch, or a suitable supported newer major. |
| We use CI secrets, not a checked-in .env file. Are we affected by the .env issue? | The advisory excludes builds without a .env file at build time, including common CI builds using platform environment variables. | Verify no environment file is present in the build directory. Still ensure no sensitive value is explicitly injected into the browser bundle. |
| We never publish Storybook. | The .env advisory’s exposure condition requires the built Storybook to be published. | That publication condition may not apply, but check CVE-2026-27148 separately if you run a vulnerable dev server. |
We only use storybook dev. |
The first advisory says the dev command is not affected by the .env build issue. | It does not exempt the dev server from the separate WebSocket advisory. Upgrade and review network exposure. |
| Our deployed application shares the repository with Storybook. | The .env advisory says deployed applications sharing the repository are not affected by that issue. | Assess the Storybook build and dev-server conditions separately; do not assume the application itself is affected by these advisories. |
| We are on Storybook 6 or earlier. | The .env advisory says Storybook 6 and below are not affected by CVE-2025-68429. The WebSocket advisory’s described functionality was introduced in 8.1. | These stated conditions do not identify your version as affected, but check official current support and security guidance before deciding whether to upgrade. |
| A secret might already be in a public build. | Published bundle files can be fetched and inspected by visitors. | Treat the secret as compromised, rotate or revoke it, then inspect the build inputs and deployment history to understand the exposure. |
| The patched version for my major is unavailable or unsupported. | The project may be on an older or unsupported branch. | Consult Storybook’s current security policy and upgrade to a supported release. Do not assume an old branch will receive a backport. |
6. Risk, reliability, and upgrade notes
These are distinct risk paths, so one fix does not substitute for the other: the .env issue concerns data in a published artifact; the WebSocket issue concerns interactions with a running development server. A production Storybook site can still matter for the first issue even though production builds are outside the second advisory.
After upgrading, verify the version resolved by the lockfile and installed in CI, then make a fresh build and publish it through the normal deployment process. If secrets were potentially exposed, patching prevents the same issue from affecting future builds but does not invalidate values already copied; rotation is the step that removes the old credentials’ usefulness. No exploitation in the wild was reported to Storybook at the publication time stated in the .env advisory; that report does not establish that exposure was impossible.
7. ScreenshotNeo as an alternative for screenshot capture
If your workflow also needs screenshots of a public Storybook or other website, ScreenshotNeo is a website screenshot API and MCP server for developers. It is separate from Storybook security remediation and does not inspect Storybook bundles, rotate credentials, or patch a development server. It can capture a URL as PNG, JPEG, WebP, or PDF, and its response identifies page verdict and billing status in headers.
One request example is below; see the ScreenshotNeo API documentation for parameters and configuration.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://storybook.js.org -o shot.webp
ScreenshotNeo removes known cookie and consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed. It also provides an MCP server with screenshot and page information tools for AI agents. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots. Sign up for 1,000 free screenshots a month, with no card required.
FAQ
Can a public Storybook reveal a secret from a .env file?
Under the conditions in CVE-2025-68429, sensitive values could be bundled into a published Storybook build. If one may have been published, rotate the affected credentials.
Does a production Storybook build have the WebSocket issue?
The CVE-2026-27148 advisory applies to the development server and says production builds are not affected by that issue.
Does upgrading remove a secret from an already published build?
No. Upgrade to prevent future affected builds, and rotate any secret that may already have been exposed.
Do these advisories prove that attackers exploited projects?
No. Storybook’s .env advisory said no exploited project had been reported to its team at publication time. That statement is time-bound and is not proof that no exposure occurred.


