Vulnerabilities
Report: CVE-2026-47068 - Cross-session PubSub topic injection via URL parameter in phoenix_storybook
CVE ID :CVE-2026-47068 Published : May 20, 2026, 2:17 p.m. | 14 minutes ago Description :Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe_live.ex reads a PubSub topic directly from params[
CVE Details
CVE ID
Published
May 20, 2026