Description
On December 11th, the Storybook team received a responsible disclosure alerting them to a potential vulnerability in certain built and published Storybooks.
The vulnerability is a bug in how Storybook handles environment variables defined in a .env file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the storybook build command.
Recommendation
Update the storybook package to the latest compatible version. Followings are version details:
Affected version(s): **>= 10.0.0, < 10.1.10 >= 9.0.0, < 9.1.17 >= 8.0.0, < 8.6.15 >= 7.0.0, < 7.6.21** Patched version(s): **10.1.10 9.1.17 8.6.15 7.6.21**
References
Could your website be exposed too?
SmartScanner can check your website for Storybook manager bundle may expose environment variables during build and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods - CVE-2026-42047
- webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior - CVE-2025-68458
- content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE - CVE-2025-55164
- Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) - CVE-2026-69263


