PatchSiren cyber security CVE debrief
CVE-2026-107303 jhipster CVE debrief
Applications generated by JHipster v9.2.0 are vulnerable to stored XSS via unrestricted Blob ContentType values. Attackers can store malicious Blob content and MIME types through the generated REST API, which are then returned to privileged users and opened as same-origin Blob documents in the generated UI, potentially leading to XSS attacks. The vulnerability arises from a trust-boundary failure across generated server and client code, allowing any authenticated user to store malicious content. This issue is particularly concerning for applications with Blob-bearing entities writable by authenticated users.
- Vendor
- jhipster
- Product
- generator-jhipster
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Developers and administrators of applications generated with JHipster v9.2.0, especially those with Blob-bearing entities writable by authenticated users, should review and update their applications to use secure content types and validate user input. They should also verify and update the Content Security Policy (CSP) to prevent XSS attacks and implement proper authorization and validation for entity creation and update operations.
Why it matters
CVE-2026-107303 is a stored XSS vulnerability in JHipster v9.2.0 that allows attackers to store malicious content and potentially lead to XSS attacks. Developers and administrators of affected applications should review and update their applications to use secure content types and validate user input.
- Potential for stored XSS attacks
- Exposure of sensitive data through malicious content
- Compromise of user sessions or privileges
- Reputation damage due to security incidents
Technical summary
The vulnerability is caused by a trust-boundary failure across generated server and client code. The generated entity REST resource accepts request bodies for entity creation and update without proper authorization, allowing any authenticated user to store malicious content. This issue is particularly concerning for applications with Blob-bearing entities writable by authenticated users. The generated `openFile` helper creates an object URL from the Blob and opens it in a new window, which can lead to XSS attacks when the Blob content and MIME type are controlled by an attacker.
Defensive priority
High priority for applications generated with JHipster v9.2.0, especially those with Blob-bearing entities writable by authenticated users.
Recommended defensive actions
- Review and update generated applications to use secure content types and validate user input.
- Implement proper authorization and validation for entity creation and update operations.
- Verify and update the Content Security Policy (CSP) to prevent XSS attacks.
- Upgrade to JHipster v9.4.0 or later to apply the fix.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is caused by a trust-boundary failure across generated server and client code. The generated entity REST resource accepts request bodies for entity creation and update without proper authorization, allowing any authenticated user to store malicious content.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107303 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107303
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107303 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107303
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Sa
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-9ffp-22j7-56r2.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/jhipster/generator-jhipster/security/advisories/GHSA-9ffp-22j7-56r2
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/jhipster/generator-jhipster/pull/34807
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/jhipster/generator-jhipster/commit/efe95edd4dedc3379735094936439410a51ce3d9
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/jhipster/generator-jhipster
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/jhipster/generator-jhipster/releases/tag/v9.4.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.