CVE-2026-107375 | JHipster Generator up to 9.3.x Reactive EntityManager EntityManager_reactive.java.ejs createOrderByFields sort sql injection

SecurityVulns

A vulnerability was found in JHipster Generator up to 9.3.x and classified as critical. The impacted element is the function createOrderByFields of the file generators/spring-boot/generators/data-relational/templates/src/main/java/package/repository/EntityManager_reactive.java.ejs of the component Reactive EntityManager. Executing a manipulation of the argument sort can lead to sql injection.

This vulnerability is registered as CVE-2026-107375. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More