Vulnerability library
Security checkJanuary 07, 2026

Storybook manager bundle may expose environment variables during build

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmstorybook

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

On December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.

The vulnerability is a bug in how Storybook handles environment variables defined in a .env file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the storybook build command.

Recommendation

Update the storybook package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 10.0.0, < 10.1.10 >= 9.0.0, < 9.1.17 >= 8.0.0, < 8.6.15 >= 7.0.0, < 7.6.21**
  • Patched version(s): **10.1.10 9.1.17 8.6.15 7.6.21**

References

Could your website be exposed too?

SmartScanner can check your website for Storybook manager bundle may expose environment variables during build and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 07, 2026