criticalVulnerability

CVE-2026-8467

### Summary An unsafe HEEx template generation vulnerability allows any unauthenticated user to execute arbitrary code on the server. The phoenix_storybook playground accepts user-controlled attribute values over WebSocket and interpolates them unsanitized into a HEEx template that is subsequently compiled and evaluated with full Elixir `Kernel` access. ### Details The vulnerability is a three-step chain: **1. Unsanitized WebSocket input (`extra_assigns_helpers.ex`)** The `psb-assign` event handler in `PhoenixStorybook.Story.PlaygroundPreviewLive` accepts arbitrary attribute names and values from unauthenticated WebSocket clients and stores them verbatim via `ExtraAssignsHelpers.handle_set_variation_assign/3`. **2. Unescaped interpolation into HEEx (`component_renderer.ex`)** `ComponentRenderer.attributes_markup/1` builds a HEEx template string by interpolating binary attribute values directly: ```elixir {name, val} when is_binary(val) -> ~s|#{name}="#{val}"| ``` No escaping of `"` or `{` is performed. A value such as `foo" injected={EXPR} bar="` breaks out of the attribute string and injects `EXPR` as an inline HEEx expression. **3. Unsandboxed evaluation (`component_renderer.ex`)** The resulting HEEx string is compiled via `EEx.compile_string/2` and evaluated via `Code.eval_quoted_with_env/3` with full `Kernel` imports and no sandbox. The injected expression executes on the server even if it causes a rendering error. ### PoC 1. Identify any story URL with a Playground tab (e.g. `/storybook/core_components/button`). 2. Connect to the Phoenix LiveView WebSocket without any authentication. 3. Join the story's LiveView channel and send a `psb-assign` event with an attribute value that escapes the HEEx attribute context and embeds an Elixir expression (e.g. a `System.cmd/2` call). 4. The server evaluates the injected expression and returns its output in the rendered response. No authentication, no special configuration, and no user interaction are required. #

Properties

ghsa_id
GHSA-55hg-8qxv-qj4p
severity
critical
summary
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
epss_score
0.00907
cve_id
CVE-2026-8467
is_ghsa_only
false
ghsa_published
2026-06-09T21:58:57Z
source_url
https://github.com/advisories/GHSA-55hg-8qxv-qj4p
epss_percentile
0.57633
ghsa_updated
2026-06-09T21:58:58Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]erlang/phoenix_storybook

AFFECTS (1)

[Software]erlang/phoenix_storybook

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph