PatchSiren

jhipster CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH jhipster CVE published 2026-10-08

CVE-2026-107375

A CVE debrief for CVE-2026-107375, a SQL injection vulnerability in JHipster-generated reactive applications. The vulnerability occurs in the paginated entity list endpoints, where the `sort` request parameter is taken verbatim from the user and concatenated into the SQL `ORDER BY` clause without quoting or validation. This allows an authenticated low-privileged user to execute arbitrary SQL, leading to f [truncated]

HIGH jhipster CVE published 2026-10-08

CVE-2026-107303

Applications generated by JHipster v9.2.0 are vulnerable to stored XSS via unrestricted Blob ContentType values. Attackers can store malicious Blob content and MIME types through the generated REST API, which are then returned to privileged users and opened as same-origin Blob documents in the generated UI, potentially leading to XSS attacks. The vulnerability arises from a trust-boundary failure across g [truncated]