File And Directory Information Exposure in Storybook - CVE-2025-68429
Published: April 28, 2026
Storybook
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into externally-accessible build artifacts in the Storybook build output when building a Storybook in a directory containing a .env file and publishing the built Storybook to the web. A remote attacker can view the published bundle source to disclose sensitive information.
Only built and published Storybooks are affected; development runtime environments and deployed applications that share a repository with Storybook are not affected.