Junglewise Threat Intelligence

CVE-2026-8467: phenixdigital phoenix_storybook code injection in playground rendering

CVE-2026-8467 · Severity: critical · CVSS 9.5 · Published 2026-05-20

Technologies: Phenix Digital Storybook. Vendors: Phenix Digital.

Executive brief

PhoenixStorybook is a tool used by developers to showcase and test UI components in Elixir-based web applications. A critical security flaw in its "playground" feature allows any user on the internet to execute arbitrary commands on the server without needing a password. This could lead to a complete takeover of the server, theft of sensitive data, or disruption of services.

Technical details

A remote code execution (RCE) vulnerability exists in phoenix_storybook versions 0.5.0 through 1.0.x. The flaw is located in the `psb-assign` event handler within `PhoenixStorybook.Story.PlaygroundPreviewLive`, which accepts unsanitized attribute values from WebSocket clients. These values are interpolated directly into a HEEx template string in `ComponentRenderer.attributes_markup/1` without escaping. Because the resulting template is compiled and evaluated using `Code.eval_quoted_with_env/3` with full Elixir `Kernel` access and no sandboxing, an attacker can inject arbitrary Elixir expressions (e.g., `System.cmd/2`) to execute operating system commands. The vulnerability is patched in version 1.1.0.

Affected products

  • phenixdigital phoenix_storybook >= 0.5.0, < 1.1.0

Timeline

  • 2026-05-20: disclosed
  • 2026-06-09: advisory: GitHub Advisory published
  • 2026-06-09: patched: Version 1.1.0 released

References