Junglewise Threat Intelligence

CVE-2026-47099: Storybook TeleJSON DOM XSS in parse function

CVE-2026-47099 · Severity: medium · CVSS 6.1 · Published 2026-05-20

Vendors: npm.

Executive brief

TeleJSON is a library used to serialize and deserialize JavaScript objects, often used in web applications for cross-frame communication. A security flaw allows an attacker to execute malicious code in a user's browser by sending a specially crafted data payload. This could lead to unauthorized actions, such as stealing session information or manipulating the content of the web page.

Technical details

A DOM-based cross-site scripting (XSS) vulnerability exists in TeleJSON's parse() function due to unsafe deserialization. The library's custom reviver processes a special '_constructor-name_' property and passes its value directly into a 'new Function()' constructor without sanitization to recreate object prototypes. An attacker can exploit this by delivering a malicious JSON payload through vectors like 'postMessage' in cross-frame communication. Successful exploitation allows for arbitrary JavaScript execution in the context of the victim's browser. The issue is fixed in version 6.0.0 by implementing a character allowlist and gating the functionality behind an 'allowFunction' option.

Affected products

  • storybookjs telejson < 6.0.0

Timeline

  • 2022: patched: Version 6.0.0 released with fix
  • 2026-05-20: disclosed: CVE-2026-47099 published

References