CVSS Score: 9.5 Published: 2026-06-09 Full Report: https://cvereports.com/reports/CVE-2026-8467
An unauthenticated remote code execution (RCE) vulnerability exists in phoenix_storybook versions 0.5.0 through 1.0.x due to improper input sanitization during HEEx template generation. By sending crafted WebSocket messages, an attacker can escape HTML attribute boundaries and execute arbitrary Elixir code.