CVE-2026-107375 | JHipster Generator up to 9.3.x Reactive EntityManager EntityManager_reactive.java.ejs createOrderByFields sort sql injection
A vulnerability was found in JHipster Generator up to 9.3.x and classified as critical. The impacted element is the function createOrderByFields of the file generators/spring-boot/generators/data-relational/templates/src/main/java/package/repository/EntityManager_reactive.java.ejs of the component Reactive EntityManager. Executing a manipulation of the argument sort can lead to sql injection.
This vulnerability is registered as CVE-2026-107375. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More