CVE-2025-4318: AWS Amplify Studio UI Component Properties Has an Input Validation Issue
The AWS Amplify Studio amplify-codegen-ui is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating component files in customers’ local applications.
An issue exists in the Amplify Studio property binding process of the amplify-codegen-ui package that could potentially allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process.
References
- aws.amazon.com/security/security-bulletins/AWS-2025-010
- blog.securelayer7.net/cve-2025-4318-aws-amplify-rce
- github.com/advisories/GHSA-hf3j-86p7-mfw8
- github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6
- github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.3
- github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8
- nvd.nist.gov/vuln/detail/CVE-2025-4318
Code Behaviors & Features
Detect and mitigate CVE-2025-4318 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →