PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107303 jhipster CVE debrief

Applications generated by JHipster v9.2.0 are vulnerable to stored XSS via unrestricted Blob ContentType values. Attackers can store malicious Blob content and MIME types through the generated REST API, which are then returned to privileged users and opened as same-origin Blob documents in the generated UI, potentially leading to XSS attacks. The vulnerability arises from a trust-boundary failure across generated server and client code, allowing any authenticated user to store malicious content. This issue is particularly concerning for applications with Blob-bearing entities writable by authenticated users.

Vendor
jhipster
Product
generator-jhipster
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Developers and administrators of applications generated with JHipster v9.2.0, especially those with Blob-bearing entities writable by authenticated users, should review and update their applications to use secure content types and validate user input. They should also verify and update the Content Security Policy (CSP) to prevent XSS attacks and implement proper authorization and validation for entity creation and update operations.

Why it matters

CVE-2026-107303 is a stored XSS vulnerability in JHipster v9.2.0 that allows attackers to store malicious content and potentially lead to XSS attacks. Developers and administrators of affected applications should review and update their applications to use secure content types and validate user input.

  • Potential for stored XSS attacks
  • Exposure of sensitive data through malicious content
  • Compromise of user sessions or privileges
  • Reputation damage due to security incidents

Technical summary

The vulnerability is caused by a trust-boundary failure across generated server and client code. The generated entity REST resource accepts request bodies for entity creation and update without proper authorization, allowing any authenticated user to store malicious content. This issue is particularly concerning for applications with Blob-bearing entities writable by authenticated users. The generated `openFile` helper creates an object URL from the Blob and opens it in a new window, which can lead to XSS attacks when the Blob content and MIME type are controlled by an attacker.

Defensive priority

High priority for applications generated with JHipster v9.2.0, especially those with Blob-bearing entities writable by authenticated users.

Recommended defensive actions

  • Review and update generated applications to use secure content types and validate user input.
  • Implement proper authorization and validation for entity creation and update operations.
  • Verify and update the Content Security Policy (CSP) to prevent XSS attacks.
  • Upgrade to JHipster v9.4.0 or later to apply the fix.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is caused by a trust-boundary failure across generated server and client code. The generated entity REST resource accepts request bodies for entity creation and update without proper authorization, allowing any authenticated user to store malicious content.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107303 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107303

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107303 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107303

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Sa

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-9ffp-22j7-56r2.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jhipster/generator-jhipster/security/advisories/GHSA-9ffp-22j7-56r2

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jhipster/generator-jhipster/pull/34807

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jhipster/generator-jhipster/commit/efe95edd4dedc3379735094936439410a51ce3d9

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jhipster/generator-jhipster

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/jhipster/generator-jhipster/releases/tag/v9.4.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.