Input Validation Flaw in AWS Amplify Studio UI Component by Amazon
CVE-2025-4318
9.5CRITICAL
What is CVE-2025-4318?
The AWS Amplify Studio UI component exhibits an input validation flaw within the aws-amplify/amplify-codegen-ui package. This vulnerability allows authenticated users with access to create or modify components to execute arbitrary JavaScript code during the component's rendering and build process. If exploited, this could lead to the execution of malicious scripts, thereby compromising the integrity of the application and potentially exposing sensitive data. Proper validation measures are essential to mitigate such risks.
Affected Version(s)
Amplify Studio 0.1.0 < 2.20.3