Blob data vulnerability in JHipster development platform
CVE-2026-107303
What is CVE-2026-107303?
JHipster, a popular development platform for modern web applications, has a vulnerability where generated applications may allow the persistence of attacker-controlled Blob data and corresponding ContentType values. This vulnerability enables attackers to exploit generated REST endpoints and potentially execute active HTML or SVG content through the application's openFile helper. If a user with write access stores such content, it can be executed under the application's origin when accessed by a privileged user. The exploitability of this issue is influenced by the application's content security policy and the Blob behavior of the target browser. Users are advised to upgrade to generator-jhipster 9.4.0 and react-jhipster 1.1.0 to mitigate this risk.
Affected Version(s)
generator-jhipster < 9.4.0
react-jhipster < 1.1.0
