Medium · 5.0 Node.js & npm GHSA-r223-96jv-q533 CVE-2026-107375
CVE-2026-107375 — JHipster generated reactive apps: SQL injection via sort parameter
Reactive applications generated by generator-jhipster that use Spring WebFlux and Spring Data R2DBC can render attacker-controlled sort parameters directly into SQL ORDER BY clauses, allowing SQL injection. The issue affects generator-jhipster introduced in 7.0.0 and is fixed in 9.4.0. (Sources: OSV, NVD) [4123, 31849]
AI summary
JHipster's generator (generator-jhipster) can produce reactive applications (Spring WebFlux + Spring Data R2DBC + SQL) whose generated repository code inserts an attacker-controlled sort parameter into SQL ORDER BY without validation or quoting, enabling SQL injection via the R2DBC simple query protocol. This advisory summarizes the impact and recommended response. [4123, 31849]
What happened
Generator-jhipster produced code for reactive applications that passes the user-supplied sort request parameter into a template helper (createOrderByFields) and renders those properties directly into the SQL ORDER BY clause without validation or quoting. Because the R2DBC simple query protocol can execute multiple statements separated by semicolons, a malicious authenticated user can use this to read, modify, or delete data, or drop tables. Non-reactive JPA applications and NoSQL backends are not affected by this root cause. [4123, 31849]
Technical cause
The generator template for reactive repositories (generated code path using Spring WebFlux and Spring Data R2DBC with a SQL database) inserts sort properties into the ORDER BY clause without validation or quoting. The R2DBC simple query protocol accepts statement separators (semicolons), which allows injection of additional SQL statements. This combination of unvalidated rendering in generated code and the R2DBC protocol is the root cause. [4123, 31849]
Who is affected
Projects generated with generator-jhipster that produce reactive applications using Spring WebFlux, Spring Data R2DBC and a SQL database are affected. Non-reactive JPA applications and NoSQL backends are outside the scope of this vulnerability. The package affected is generator-jhipster. [4123, 31849]
Affected versions
The vulnerability is present in generator-jhipster introduced in 7.0.0 and is fixed in 9.4.0. [4123, 31849]
Fixes and mitigation
A vendor fix is available. The issue is fixed in generator-jhipster 9.4.0. If you can update, apply the vendor update that contains the fix. Where immediate update is not possible, mitigate risk by validating and strictly limiting permitted sort property names on the server side and by rejecting or stripping statement separators (semicolon) from sort input before it reaches generated queries. [4123, 31849]
Recommended action
Upgrade generator-jhipster to 9.4.0 as soon as practicable. Audit reactive endpoints generated for WebFlux + R2DBC + SQL to ensure sort parameters are validated and cannot contain statement separators or injected SQL. For high-risk deployments, consider temporarily disabling or restricting paginated list endpoints until the update or mitigation is in place. [4123, 31849]
PatchBriefing score
5.0 / 10 · Medium
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Why this score
This advisory carries CVSS v3.1 base score 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vector shows remote network attack (AV:N) with low attack complexity, but it requires at least limited privileges (PR:L). Confidentiality, integrity and availability impacts are high. PatchWire score is 5.0 (driven primarily by the CVSS base score and the fact that no user interaction is required). [4123, 31849]
Affected versions
- generator-jhipster ≥ 7.0.0 < 9.4.0
- vulnerable
- ≥ 9.4.0
- patched
Reported fixes
A vendor fix is available. The issue is fixed in generator-jhipster 9.4.0. If you can update, apply the vendor update that contains the fix. Where immediate update is not possible, mitigate risk by validating and strictly limiting permitted sort property names on the server side and by rejecting or stripping statement separators (semicolon) from sort input before it reaches generated queries. [4123, 31849]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email