[CVE-2026-27148] Persistent XSS/RCE using WebSockets in Storybook’s dev server
aikido.dev | blog | CVE-2026-27148 | #ai-security | #rce | #xss | #cve | #websocket | #ai-pentesting | #storybook
Summary
A WebSocket hijacking flaw in Storybook's dev server (CVE-2026-27148, CVSS 8.9) enables persistent XSS and RCE that could reach production builds. Patched in 7.6.23, 8.6.17, 9.1.19, and 10.2.10.
- Published
- Collected
Skip to content