Junglewise Threat Intelligence

CVE-2025-68429: Storybook environment variable exposure in build artifacts

CVE-2025-68429 · Severity: low · CVSS 3.1 · Published 2025-12-18

Technologies: Storybook.

Executive brief

Storybook, a popular tool for developing and documenting UI components, accidentally bundles sensitive environment variables from .env files into published web artifacts when building projects. Anyone viewing the published Storybook's source code can read these exposed secrets, which may include API keys, database passwords, and other credentials. Organizations that built and published Storybooks containing .env files with secrets should immediately rotate those credentials and upgrade to patched versions.

Technical details

The vulnerability is an information disclosure issue (CWE-200, CWE-538, CWE-541) in how Storybook processes environment variables during the build step. Environment variables defined in .env or .env.local files are unexpectedly bundled into the output artifacts generated by the `storybook build` command. When these built artifacts are deployed to a web server, the bundle source code is publicly viewable, exposing any secrets contained in those variables. The issue affects Storybook versions 7.0.0 and above only when: a .env file with secrets is present during the build, and the resulting build is published to the web. Common CI/CD setups that provide secrets via environment variables (not .env files) are unaffected. Patches are available in versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 and above.

Affected products

  • Storybook Storybook 7.0.0 to 7.6.20, 8.0.0 to 8.6.14, 9.0.0 to 9.1.16, 10.0.0 to 10.1.9

Timeline

  • 2025-12-18: disclosed
  • 2025-12-18: patched: Patched versions released: 7.6.21, 8.6.15, 9.1.17, 10.1.10+

References