5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether generator-jhipster is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 2.9
CVE-2025-43712
Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter
CRITICAL 9.8
CVE-2019-16303
Critical severity vulnerability that affects generator-jhipster
HIGH 7.5
CVE-2015-20110
generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character
HIGH 8.1
CVE-2022-24815
SQL Injection when creating an application with Reactive SQL backend
HIGH 8.1
GHSA-mc84-xr9p-938r
High severity vulnerability that affects generator-jhipster
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes