Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork9.8k
Security: storybookjs/storybook
Security
SECURITY.md
We release patches for fixing security vulnerabilities, primarily focusing on the latest release only.
In the event of a high-risk vulnerability, we may backport the security fixes to the minor versions of the software, starting from the latest minor version up to the latest major release. The decision to backport security fixes to older versions will be made based on a risk assessment and the feasibility of implementing the patch in those versions.
To report a vulnerability, you can reach out to the maintainers directly on Twitter:https://twitter.com/storybookjs or Bluesky:https://bsky.app/profile/storybook.js.org
When we fix a security issue, we will post a security advisory on Github/NPM, describe the change in therelease notes, and also announce notify the community onour Discord.
- Exposure of environment variables from .env in published StorybookGHSA-8452-54wp-rmv6 published
Dec 17, 2025 byvanessayuennHigh