CVE-2025-68429
Storybook manager bundle may expose environment variables during build
๐จ A sneaky little oversight in Storybook could expose your `.env` secrets during builds! If your project runs `storybook build`, you might be giving away the keys to the kingdom! ๐๐ฑ Think of it like accidentally including confidential notes in a delivery of your latest project presentation โ those notes weren't meant for public eyes! If you build your Storybook in a directory with a `.env` file, it might just slip through the cracks and end up viewable by anyone online. If exposed, sensitive information like API keys and database credentials could be seen by anyone accessing your Storybook deployment. This is absolutely devastating for your project's security, potentially leading to unauthorized access and data breaches! ๐ฅ
HIGH