Storybook React-node XSS → authenticated password creation

One click. New credential.

A cross-origin Storybook message revives an attacker-supplied React node. Its srcDoc executes under storybook.arbor.linktr.ee and submits Linktree’s cookie-authenticated CreatePassword mutation.

Replay console Ready

Ephemeral takeover credential

The attacker-known password below is generated locally. Click once to open the vulnerable Storybook story and dispatch the authenticated mutation automatically.

Ready. No target request has been sent.
01

Before

Use a Google-backed controlled identity with no password. The account presents the Create password state.

02

Dispatch

The single click opens Storybook and sends one credentialed text/plain GraphQL mutation. The response remains opaque.

03

After

Log out, then authenticate in a fresh client using the controlled email and generated password. The verified end state is /admin.