CVE-2026-27148 | storybookjs storybook up to 7.6.22/8.6.16/9.1.18/10.2.9 WebSocket Message componentFilePath injection (GHSA-mjf5-7g4m-gx5w)
A vulnerability labeled as problematic has been found in storybookjs storybook up to 7.6.22/8.6.16/9.1.18/10.2.9. Affected is an unknown function of the component WebSocket Message Handler. Executing a manipulation of the argument componentFilePath can lead to injection.
This vulnerability is handled as CVE-2026-27148. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.