Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-68429

Опубликовано: 17 дек. 2025
Источник: nvd
CVSS3: 7.3
CVSS3: 5.3
EPSS Низкий

Описание

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a .env file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the storybook build command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. For a project to potentially be vulnerable to this issue, it must build the Storybook (i.e. run storybook build directly or indirectly) in a directory that contains a .env file (including variants like .env.local) and publish the built Storybook to the web. Storybooks built without a .env file at build time are not affected, including common CI-based builds where secrets are provided via platform en

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
Версия от 7.0.0 (включая) до 7.6.21 (исключая)
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
Версия от 8.0.0 (включая) до 8.6.15 (исключая)
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
Версия от 9.0.0 (включая) до 9.1.17 (исключая)
cpe:2.3:a:storybook:storybook:*:*:*:*:*:node.js:*:*
Версия от 10.0.0 (включая) до 10.1.10 (исключая)

EPSS

Процентиль: 18%
0.00261
Низкий

7.3 High

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
redhat
8 месяцев назад

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. For a project to potentially be vulnerable to this issue, it must build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`) and publish the built Storybook to the web. Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform...

CVSS3: 7.3
github
8 месяцев назад

Storybook manager bundle may expose environment variables during build

EPSS

Процентиль: 18%
0.00261
Низкий

7.3 High

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-200