Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.2 Node.js & npm GHSA-9ffp-22j7-56r2 CVE-2026-107303

Generated applications allow stored XSS via Blob ContentType (CVE-2026-107303)

Generated JHipster applications can persist attacker-controlled Blob data and ContentType values that are later opened as same-origin object URLs, allowing stored XSS when privileged users view them. Fixed in generator-jhipster 9.4.0 and react-jhipster 1.1.0. [Sources: 4120, 31840]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

JHipster-generated applications may expose a stored cross-site scripting (XSS) vector when attacker-controlled Blob content and its ContentType are persisted and later opened as same-origin object URLs. The issue is tracked as CVE-2026-107303 and addressed in generator-jhipster 9.4.0 and react-jhipster 1.1.0. [Sources: 4120, 31840]

What happened

Generated applications created by JHipster could persist attacker-controlled Blob data together with a companion ContentType value, return them through generated REST endpoints, and pass them to the generated openFile helper. That helper uses the returned ContentType as the browser Blob MIME type and opens an object URL; this allows stored HTML or SVG to execute under the application origin when a privileged user opens the object URL. The issue is recorded as CVE-2026-107303. [Sources: 4120, 31840]

Technical cause

The generated openFile helper applied the returned ContentType value as the Blob MIME type and opened an object URL without restricting or validating that ContentType. This made it possible for stored HTML or SVG content to be executed under the same origin. The underlying weakness is categorized under CWE-79. [Sources: 4120, 31840]

Why it matters

A normal authenticated user with write access to a Blob-bearing entity could store active HTML or SVG that executes as same-origin content when opened by a privileged user. Exploitability depends on the generated application's content security policy and target‑browser Blob behavior. The vulnerability has a CVSS v3.1 base score of 7.6. [Sources: 4120, 31840]

Who is affected

Applications generated with generator-jhipster and react-jhipster as shipped before their fixes are affected when they include the generated code path that persists and opens Blob data. [Sources: 4120, 31840]

Affected versions

The issue affects generator-jhipster from 0 up to but not including 9.4.0, and react-jhipster from 0 up to but not including 1.1.0. [Sources: 4120, 31840]

Fixes and mitigation

A vendor fix is available: generator-jhipster 9.4.0 and react-jhipster 1.1.0 contain fixes for this issue. The advisory records that a fix is available. [Sources: 4120, 31840]

Discovery and timeline

The OSV and NVD entries for CVE-2026-107303 were published in October 2026 (see source entries). The advisory record lists publication and modification metadata. No discoverer or exploit timeline is specified in the provided facts. [Sources: 4120, 31840]

Recommended action

Apply the available updates: move generator-jhipster to 9.4.0 (or later) and react-jhipster to 1.1.0 (or later). If you cannot immediately update, be aware that exploitability depends on the application content security policy and browser Blob behavior; take that into account when evaluating exposure. [Sources: 4120, 31840]

PatchBriefing score

4.2 / 10 · Medium

Official CVSS: 7.6

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Why this score

The advisory lists a CVSS v3.1 base score of 7.6 (vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). Patchwire's aggregated score for this advisory is 4.2, which reflects the CVSS base score contribution (4.18) together with the absence of indicators such as known exploitation or public exploits in the provided facts. [Sources: 4120, 31840]

Affected versions

generator-jhipster ≥ 0 < 9.4.0
vulnerable
≥ 9.4.0
patched
react-jhipster ≥ 0 < 1.1.0
vulnerable
≥ 1.1.0
patched

Reported fixes

A vendor fix is available: generator-jhipster 9.4.0 and react-jhipster 1.1.0 contain fixes for this issue. The advisory records that a fix is available. [Sources: 4120, 31840]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
Generated applications allow stored XSS via Blob ContentType (CVE-2026-107303)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email