
We found results for “”
CVE-2025-4318
Good to know:


Date: May 5, 2025
The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CWE-95Top Fix

Upgrade Version
Upgrade to version @aws-amplify/codegen-ui - 2.20.3;@aws-amplify/codegen-ui-react - 2.20.3;https://github.com/aws-amplify/amplify-codegen-ui.git - v2.20.3
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |