The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-13500 The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 03:30:00 +0900


Sat, 19 Jul 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00064}

epss

{'score': 0.00067}


Tue, 10 Jun 2025 10:30:00 +0900


Tue, 06 May 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 May 2025 03:30:00 +0900

Type Values Removed Values Added
Description The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
Title Input validation issue in AWS Amplify Studio UI component properties
Weaknesses CWE-95
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2025-10-14T18:15:57.700Z

Reserved: 2025-05-05T14:03:53.695Z

Link: CVE-2025-4318

cve-icon Vulnrichment

Updated: 2025-06-10T00:56:59.266Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-05T19:15:57.847

Modified: 2025-10-14T19:15:42.347

Link: CVE-2025-4318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses