Input Validation Flaw in AWS Amplify Studio UI Component by Amazon
CVE-2025-4318
9.5CRITICAL
What is CVE-2025-4318?
The AWS Amplify Studio UI component exhibits an input validation flaw within the aws-amplify/amplify-codegen-ui package. This vulnerability allows authenticated users with access to create or modify components to execute arbitrary JavaScript code during the component's rendering and build process. If exploited, this could lead to the execution of malicious scripts, thereby compromising the integrity of the application and potentially exposing sensitive data. Proper validation measures are essential to mitigate such risks.
Affected Version(s)
Amplify Studio 0.1.0 < 2.20.3
References
CVSS V4
Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved