1.
A WebSocket hijacking flaw in Storybook's dev server (CVE-2026-27148, CVSS 8.9) enables persistent XSS and RCE that could reach production builds. Patched in 7.6.23, 8.6.17, 9.1.19, and 10.2.10.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-27148.