Answer in brief
CVE-2026-107303 records a High severity (CVSS 7.6) vulnerability in JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob. The current sources do not mark it as known exploited. The current feed maps jhipster/generator-jhipster (generic), jhipster/react-jhipster (generic), generator-jhipster (npm), react-jhipster (npm). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps jhipster/generator-jhipster (generic), jhipster/react-jhipster (generic), generator-jhipster (npm), react-jhipster (npm). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| jhipster/generator-jhipstergeneric | <9.4.0 | 9.4.0 |
| jhipster/react-jhipstergeneric | <1.1.0 | 1.1.0 |
| generator-jhipsternpm | <9.4.0 | 9.4.0 |
| react-jhipsternpm | <=1.0.3 | 1.1.0 |
Published upstream
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/client/generators/common/templates/src/main/webapp/app/shared/jhipster/data-utils.ts.ejs. The helper uses the returned ContentType as the browser Blob MIME type and opens an object URL, so a normal authenticated user with write access to a Blob-bearing entity can store active HTML or SVG content that may execute under the application origin when a privileged user opens it. Exploitability depends on the generated application's content security policy and target-browser Blob behavior. This issue is fixed in generator-jhipster 9.4.0 and react-jhipster 1.1.0.
Quoted source text, attributed separately from HOL analysis.