Medium · 4.2 Node.js & npm GHSA-9ffp-22j7-56r2 CVE-2026-107303
Generated applications allow stored XSS via Blob ContentType (CVE-2026-107303)
Generated JHipster applications can persist attacker-controlled Blob data and ContentType values that are later opened as same-origin object URLs, allowing stored XSS when privileged users view them. Fixed in generator-jhipster 9.4.0 and react-jhipster 1.1.0. [Sources: 4120, 31840]
AI summary
JHipster-generated applications may expose a stored cross-site scripting (XSS) vector when attacker-controlled Blob content and its ContentType are persisted and later opened as same-origin object URLs. The issue is tracked as CVE-2026-107303 and addressed in generator-jhipster 9.4.0 and react-jhipster 1.1.0. [Sources: 4120, 31840]
What happened
Generated applications created by JHipster could persist attacker-controlled Blob data together with a companion ContentType value, return them through generated REST endpoints, and pass them to the generated openFile helper. That helper uses the returned ContentType as the browser Blob MIME type and opens an object URL; this allows stored HTML or SVG to execute under the application origin when a privileged user opens the object URL. The issue is recorded as CVE-2026-107303. [Sources: 4120, 31840]
Technical cause
The generated openFile helper applied the returned ContentType value as the Blob MIME type and opened an object URL without restricting or validating that ContentType. This made it possible for stored HTML or SVG content to be executed under the same origin. The underlying weakness is categorized under CWE-79. [Sources: 4120, 31840]
Why it matters
A normal authenticated user with write access to a Blob-bearing entity could store active HTML or SVG that executes as same-origin content when opened by a privileged user. Exploitability depends on the generated application's content security policy and target‑browser Blob behavior. The vulnerability has a CVSS v3.1 base score of 7.6. [Sources: 4120, 31840]
Who is affected
Applications generated with generator-jhipster and react-jhipster as shipped before their fixes are affected when they include the generated code path that persists and opens Blob data. [Sources: 4120, 31840]
Affected versions
The issue affects generator-jhipster from 0 up to but not including 9.4.0, and react-jhipster from 0 up to but not including 1.1.0. [Sources: 4120, 31840]
Fixes and mitigation
A vendor fix is available: generator-jhipster 9.4.0 and react-jhipster 1.1.0 contain fixes for this issue. The advisory records that a fix is available. [Sources: 4120, 31840]
Discovery and timeline
The OSV and NVD entries for CVE-2026-107303 were published in October 2026 (see source entries). The advisory record lists publication and modification metadata. No discoverer or exploit timeline is specified in the provided facts. [Sources: 4120, 31840]
Recommended action
Apply the available updates: move generator-jhipster to 9.4.0 (or later) and react-jhipster to 1.1.0 (or later). If you cannot immediately update, be aware that exploitability depends on the application content security policy and browser Blob behavior; take that into account when evaluating exposure. [Sources: 4120, 31840]
PatchBriefing score
4.2 / 10 · Medium
Official CVSS: 7.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Why this score
The advisory lists a CVSS v3.1 base score of 7.6 (vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). Patchwire's aggregated score for this advisory is 4.2, which reflects the CVSS base score contribution (4.18) together with the absence of indicators such as known exploitation or public exploits in the provided facts. [Sources: 4120, 31840]
Affected versions
- generator-jhipster ≥ 0 < 9.4.0
- vulnerable
- ≥ 9.4.0
- patched
- react-jhipster ≥ 0 < 1.1.0
- vulnerable
- ≥ 1.1.0
- patched
Reported fixes
A vendor fix is available: generator-jhipster 9.4.0 and react-jhipster 1.1.0 contain fixes for this issue. The advisory records that a fix is available. [Sources: 4120, 31840]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email