CVE-2025-4318
A security flaw in the aws-amplify/amplify-codegen-ui package allows for the execution of unauthorized code. This occurs because the software does not properly validate certain property expressions used in the AWS Amplify Studio UI components.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the aws-amplify/amplify-codegen-ui package who have the ability to create or modify components in the AWS Amplify Studio UI.
Real-world impact
An attacker with permission to create or modify components could inject and run malicious JavaScript code. This could compromise the component rendering process and the build process.
Why this severity
The critical severity score reflects that an attacker can execute arbitrary code, which can lead to a total loss of confidentiality, integrity, and availability of the affected system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 5, 2025 · May 5, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.