Skip to main content

CVE-2026-107375: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in jhipster generator-jhipster

0
High
Published: 10/08/2026 (10/08/2026, 17:40:37 UTC)
Source: CVE Database V5
Vendor/Project: jhipster
Product: generator-jhipster

Description

# SQL Injection in the `sort` Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applications - **Product**: jhipster/generator-jhipster (npm package `generator-jhipster`) - **Affected versions**: v7.0.0 through v9.2.0 - **Component**: generated reactive-application code, template `EntityManager_reactive.java.ejs` - **Report date**: 2026-08-29 --- ## 1. Summary Every reactive (Spring WebFlux + Spring Data R2DBC + SQL) application generated by `generator-jhipster` contains an SQL injection in the paginated entity list endpoints (`GET /api/<entity>?sort=...`). The `sort` request parameter is taken verbatim from the user and concatenated into the SQL `ORDER BY` clause without quoting or validation. Because the generated query has no bound parameters, the R2DBC drivers execute it via the **simple query protocol**, so `;`-separated extra statements are run against the database. A single authenticated low-privileged user (including an account obtained through the default self-registration flow) can therefore **execute arbitrary SQL**: read any table (including `jhi_user` password hashes), modify or delete data, and drop tables (full C/I/A impact). Independently reproduced end-to-end on the default dev database (H2) and the default production database (PostgreSQL 16). The JPA (non-reactive) path is **not** affected: Spring Data JPA validates sort property names against the entity metamodel. NoSQL backends are out of scope of this root cause. ## 2. Root Cause The generator template `generators/spring-boot/generators/data-relational/templates/src/main/java/_package_/repository/EntityManager_reactive.java.ejs` (lines 240–253) writes `createOrderByFields(...)`, which renders the user-supplied sort property directly as an unquoted `SqlIdentifier`: ```java private static Collection<? extends OrderByField> createOrderByFields(Table table, Sort sortToUse) { List<OrderByField> fields = new ArrayList<>(); for (Sort.Order order : sortToUse) { String propertyName = order.getProperty(); // attacker controlled (?sort=...) OrderByField orderByField = !propertyName.contains(".") ? OrderByField.from(table.column(propertyName).as(EntityManager.ALIAS_PREFIX + propertyName)) : createOrderByField(propertyName); fields.add(order.isAscending() ? orderByField.asc() : orderByField.desc()); } return fields; } ``` The generated app configures `SqlRenderer.create(factory.createRenderContext())` with the default naming strategy, so unquoted identifiers are rendered **verbatim**. With `?sort=id;DROP TABLE product;--` the alias renders into: ```sql SELECT e.id AS e_id, e.name AS e_name, e.price AS e_price FROM product e ORDER BY e_id;DROP TABLE product;-- ASC LIMIT 20 OFFSET 0 ``` ## 3. Verification A real application was generated from this repository (`git clone` of the submitted source, v9.2.0), built with Spring Boot 4.1.1, and run against both H2 and PostgreSQL 16. | Step | H2 (dev default) | PostgreSQL 16 (prod default) | | ------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------- | -------------------------------------------------- | | Error probe `sort=name%27` | 500; SQL echoed with raw `'` in `ORDER BY e_name'` | 500; r2dbc-postgresql parse error echoing full SQL | | Exfiltrate admin hash via `;UPDATE product SET name=(SELECT password_hash FROM jhi_user ...);--` | HTTP 200; `name` becomes `$2a$10$gSAhZrxMllrbgj/kkK9UceBPpChGWJA7SYIb1Mqo.n5aNLq1/oRrC` | HTTP 200; same hash read back | | `;DROP TABLE product;--` | HTTP 200; table gone, subsequent list → 500 | HTTP 200; table gone, subsequent list → 500 | All payloads executed with a token carrying only `ROLE_USER`. **No other vulnerability or privileged account is required.** ## 4. Impact CWE-89 SQL Injection. Confidentiality (arbitrary read, incl. `jhi_user` password hashes), Integrity (arbitrary writes), Availability (table drops). The affected code is produced by default for `reactive: true` + SQL database + paginated entity (the default for monoliths and microservices). Applications must be regenerated after a fix. ## 5. Fix Recommendation In `EntityManager.createOrderByFields`, validate each sort property against the entity's persistent metamodel (allow only known column names) or render it as a quoted `SqlIdentifier`; never concatenate raw property strings into SQL. Ship the fix in the generator and advise affected applications to re

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

jhipster

generator-jhipster

Affected versions
>=7.0.0 <9.4.0
generator-jhipster
pkg:npm/generator-jhipster
Affected versions
>=7.0.0 <9.4.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 18:03:30 UTC

Technical Analysis

CVE-2026-107375 is an SQL injection vulnerability in JHipster generator-jhipster affecting reactive applications generated with Spring WebFlux, Spring Data R2DBC, and SQL databases from versions 7.0.0 up to 9.4.0. The vulnerability occurs because the generated code directly incorporates attacker-controlled sort request parameters into the SQL ORDER BY clause without validation or quoting. The R2DBC simple query protocol allows execution of multiple statements separated by semicolons, enabling attackers with normal authenticated access to execute arbitrary SQL commands, including reading sensitive tables, modifying or deleting data, or dropping tables. Non-reactive JPA applications and NoSQL backends are not vulnerable. The vulnerability was fixed in version 9.4.0.

Potential Impact

An attacker with normal authenticated user privileges can exploit this vulnerability to perform SQL injection attacks, potentially reading sensitive data, modifying or deleting database records, or dropping entire tables. This compromises confidentiality, integrity, and availability of the affected database. The vulnerability does not affect non-reactive JPA applications or NoSQL backends.

Mitigation Recommendations

Upgrade generator-jhipster to version 9.4.0 or later where this vulnerability is fixed. Until then, avoid using vulnerable versions for reactive applications with Spring WebFlux, Spring Data R2DBC, and SQL databases. No other mitigation or temporary fix is indicated in the advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T21:07:54.987Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7d8742cdf04f6562d26bf

Added to database: 10/08/2026, 17:52:52 UTC

Last enriched: 10/08/2026, 18:03:30 UTC

Last updated: 10/08/2026, 21:48:48 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses