Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteTwo Storybook security advisories require different responses: CVE-2025-68429 can expose secrets in a published Storybook build when a local .env file is present during the build, while CVE-2026-27148 affects the development server’s WebSocket origin checks. Upgrade to a branch release that fixes both issues, investigate whether a published build contained secrets, rotate any potentially exposed credentials, and make sure a development server is not unnecessarily reachable from the public internet.
Which Storybook security issues should developers check?
The advisories concern different components and exposure conditions. The first, published by Storybook on December 17, 2025, is about environment variables from .env files ending up in build artifacts. The second, published as GitHub advisory GHSA-mjf5-7g4m-gx5w on February 25, 2026, is about WebSocket connections to the development server. A production Storybook build is not affected by the WebSocket issue, and the .env advisory does not affect storybook dev. Storybook’s .env security advisory and the GitHub WebSocket advisory describe the distinct cases.
| Advisory | Component at issue | When exposure is possible | Primary response |
|---|---|---|---|
| CVE-2025-68429 | Published Storybook build | Storybook 7.0.0 or above is built in a directory with a .env file containing secrets, and the resulting Storybook is published. |
Check published artifacts and rotate potentially exposed secrets; upgrade before publishing again. |
| CVE-2026-27148 | Storybook development server WebSocket functionality | A developer visits a malicious website while a vulnerable local dev server is running, or a vulnerable server is publicly reachable. | Upgrade to the fixed branch release and review public accessibility of dev servers. |
Can Storybook expose secrets from a .env file?
It can under the specific conditions identified in CVE-2025-68429. The project must use Storybook 7.0.0 or later, the build must run in a directory containing a .env file (including variants such as .env.local), that file must contain sensitive secrets, and the generated Storybook must be published to the web. If secrets were included in a published bundle, treat them as compromised. The advisory states that no exploited project had been reported to the Storybook team at the time it was published; that does not establish that every published bundle is safe.
The advisory says builds made without a .env file at build time are not affected, including common CI builds where secrets are supplied through the platform’s environment variables. It also excludes storybook dev, deployed applications that share the repository, and Storybook 6 and earlier. These exclusions apply to this particular advisory, not necessarily to other security issues.
Recommended Free Tools
#1 Best Overall
What to do if a published build may contain secrets
- Identify Storybook versions and build environments used on developer machines and in CI.
- Check whether a build ran in a directory containing
.env,.env.local, or another environment file with sensitive values. - Inspect published Storybook output and, if secrets may have been included, rotate the affected keys or credentials. Remove or replace the exposed build where practical.
- Upgrade the local and CI Storybook installations before the next publication.
- Keep secrets out of any environment values that are included in the generated client-side bundle.
Storybook notes that projects relying on the previous undocumented environment-variable behavior can use the STORYBOOK_ prefix or Storybook’s env configuration property for values that need to be available to the Storybook build. These are not safe places for secrets: anything included in the bundle should be treated as visible to its recipients.
Is Storybook’s development server vulnerable to WebSocket hijacking?
Yes, vulnerable development-server versions are affected by CVE-2026-27148. The advisory says the server’s WebSocket functionality does not validate the origin of incoming connections. An attacker’s website can send WebSocket messages to a developer’s local Storybook instance if the developer visits that malicious site while the vulnerable server is running; the described scenario does not require further interaction. A dev server intentionally exposed to the public internet may be at greater risk because an attacker can connect directly. The advisory rates the issue High and gives it an overall CVSS score of 8.9. Production builds are not affected by this WebSocket vulnerability.
Rank #2
The advisory says the exploitable functionality was introduced in Storybook 8.1, and that the fix was also applied to 7.x as a precaution. Regardless of that introduction point, use the patched release for the project’s branch rather than relying on the assumption that an older release is safe.
Which Storybook versions fix both advisories?
The patched minimum differs between the two issues. For a branch covered by both advisories, the later WebSocket fix sets the higher minimum shown below. These are the fixed releases listed by Storybook, not a guarantee that a branch is still supported or that no later security fixes exist.
Free tools Windows power users keep installed
One-click scans. No signup required.
| Storybook branch | CVE-2025-68429 .env fix | CVE-2026-27148 WebSocket fix | Minimum listed release covering both |
|---|---|---|---|
| 7.x | 7.6.21 | 7.6.23 | 7.6.23 |
| 8.x | 8.6.15 | 8.6.17 | 8.6.17 |
| 9.x | 9.1.17 | 9.1.19 | 9.1.19 |
| 10.x | 10.1.10 | 10.2.10 | 10.2.10 |
Confirm the applicable release and current support status against the .env advisory and WebSocket advisory before upgrading. Storybook’s maintenance policy says the latest major receives security fixes, the previous two majors receive backports for High or Critical issues, and older versions are unsupported.
Developer checklist for remediation
- Inventory: identify versions in package manifests, lockfiles, developer environments, and CI.
- Patch: upgrade to at least the listed release for the relevant branch that fixes both advisories, and confirm the branch remains supported.
- Assess build exposure: determine whether any published build was made with a secret-bearing
.envfile present. - Rotate if needed: revoke or rotate credentials that may have been bundled; do not wait for evidence of misuse.
- Reduce dev-server exposure: check whether any development server is reachable from the public internet and restrict access when public reachability is not needed.
- Prevent recurrence: keep secrets out of values bundled into Storybook, and update both developer machines and CI before the next build or publication.
Or skip the browser setup
For teams documenting a fixed Storybook instance or capturing a published component library, ScreenshotNeo is a website screenshot API and MCP server for developers. It does not replace patching Storybook or investigating secret exposure.
Rank #4
One GET request returns a screenshot or PDF. See the ScreenshotNeo documentation for API options.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://storybook.example.com -o shot.webp
- Cookie and consent banners, newsletter popups, and chat widgets are removed before capture; each cleanup step can be turned off.
- Bot checks and CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed; response headers identify the page verdict and billing status.
- An MCP server provides
take_screenshot,get_page_info, andcapture_pdftools for AI agents. - The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Frequently Asked Questions
Does the .env advisory mean every Storybook project using environment variables is vulnerable?
No. CVE-2025-68429 requires a secret-bearing .env file to be present when building a published Storybook, along with the affected Storybook version. The advisory distinguishes this from secrets supplied through common CI platform environment variables when no .env file is present.
Does the WebSocket advisory affect a published Storybook site?
No. CVE-2026-27148 concerns the development server’s WebSocket functionality; the advisory says production builds are not affected.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

