Storybook versions 7-10 contain a vulnerability where environment variables from .env files could be unexpectedly bundled into published builds, potentially exposing secrets. The issue affects projects that build Storybook with .env files present and publish to the web. Patches are available for versions 7.6.21+, 8.6.15+,

5m read time From storybook.js.org
Post cover image
Table of contents
Who is impacted?Recommended actionsIssue details

Sort: