The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 05 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 05 May 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process. | |
Title | Input validation issue in AWS Amplify Studio UI component properties | |
Weaknesses | CWE-95 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: AMZN
Published: 2025-05-05T18:16:34.075Z
Updated: 2025-06-10T00:56:59.266Z
Reserved: 2025-05-05T14:03:53.695Z
Link: CVE-2025-4318

Updated: 2025-06-10T00:56:59.266Z

Status : Awaiting Analysis
Published: 2025-05-05T19:15:57.847
Modified: 2025-06-10T01:15:23.483
Link: CVE-2025-4318

No data.