Storybook
Read post

Security advisory

Storybook versions 7-10 contain a vulnerability where environment variables from .env files could be unexpectedly bundled into published builds, potentially exposing secrets. The issue affects projects that build Storybook with .env files present and publish to the web. Patches are available for versions 7.6.21+, 8.6.15+, 9.1.17+, and 10.1.10+. Users should rotate any exposed secrets and upgrade immediately before publishing again.

    #security#javascript#vulnerability#storybook
Dec 17, 2025•5m read time•From storybook.js.org
Post cover image
Table of contents
Who is impacted?Recommended actionsIssue details
5.6K Impressions
Storybook's image
Storybook

Storybook is an open-source tool for developing UI components in isolation for React, Vue, and Angul...

961 Followers

•

1.2K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard