Blob data vulnerability in JHipster development platform
CVE-2026-107303

7.6HIGH

Key Information:

Vendor

Jhipster

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107303?

JHipster, a popular development platform for modern web applications, has a vulnerability where generated applications may allow the persistence of attacker-controlled Blob data and corresponding ContentType values. This vulnerability enables attackers to exploit generated REST endpoints and potentially execute active HTML or SVG content through the application's openFile helper. If a user with write access stores such content, it can be executed under the application's origin when accessed by a privileged user. The exploitability of this issue is influenced by the application's content security policy and the Blob behavior of the target browser. Users are advised to upgrade to generator-jhipster 9.4.0 and react-jhipster 1.1.0 to mitigate this risk.

Affected Version(s)

generator-jhipster < 9.4.0

react-jhipster < 1.1.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.