Input Validation Flaw in AWS Amplify Studio UI Component by Amazon
CVE-2025-4318

9.5CRITICAL

Key Information:

Vendor

Amazon

Vendor
CVE Published:
5 May 2025

What is CVE-2025-4318?

The AWS Amplify Studio UI component exhibits an input validation flaw within the aws-amplify/amplify-codegen-ui package. This vulnerability allows authenticated users with access to create or modify components to execute arbitrary JavaScript code during the component's rendering and build process. If exploited, this could lead to the execution of malicious scripts, thereby compromising the integrity of the application and potentially exposing sensitive data. Proper validation measures are essential to mitigate such risks.

Affected Version(s)

Amplify Studio 0.1.0 < 2.20.3

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.