CVE-2026-107303
Received Received - Intake

Stored XSS in JHipster Generated Applications

Vulnerability report for CVE-2026-107303, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/client/generators/common/templates/src/main/webapp/app/shared/jhipster/data-utils.ts.ejs. The helper uses the returned ContentType as the browser Blob MIME type and opens an object URL, so a normal authenticated user with write access to a Blob-bearing entity can store active HTML or SVG content that may execute under the application origin when a privileged user opens it. Exploitability depends on the generated application's content security policy and target-browser Blob behavior. This issue is fixed in generator-jhipster 9.4.0 and react-jhipster 1.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
jhipster generator-jhipster < 9.4.0
jhipster react-jhipster < 1.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects JHipster, a platform for generating web applications. It allows attackers with write access to store malicious HTML or SVG content in Blob data. When a privileged user opens this content via a generated REST endpoint or openFile helper, the browser may execute the content under the application's origin due to improper handling of ContentType values as MIME types.

Detection Guidance

Detecting this vulnerability requires checking if your JHipster-generated application uses versions prior to 9.4.0 (generator-jhipster) or 1.1.0 (react-jhipster). Inspect package.json files for dependencies and compare versions. Look for applications exposing REST endpoints handling Blob data with ContentType values.

Impact Analysis

If you use a vulnerable version of JHipster, an attacker with write access could inject malicious content that executes when opened by a privileged user. This could lead to unauthorized actions, data theft, or further compromise of the application, depending on the user's privileges and the application's content security policy.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR (data protection) or HIPAA (health information privacy) requirements. Organizations using vulnerable JHipster versions may face compliance violations, legal penalties, or reputational damage if exploited.

Mitigation Strategies

Upgrade generator-jhipster to version 9.4.0 or later and react-jhipster to version 1.1.0 or later. Review and update Content Security Policy (CSP) rules to restrict execution of HTML/SVG content from untrusted sources. Audit applications for Blob-bearing entities and sanitize inputs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107303. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart