@aws-amplify/codegen-ui-react is vulnerable to Cross-site Scripting (XSS)
95
Critical Risk
Affected versions of this package fail to properly sanitize expression bindings when recursively rendering collection-type components, allowing malicious input to be processed unsafely. An attacker can craft a malicious component with injected expressions or scripts, which Amplify Studio will render without sanitization, potentially leading to cross-site scripting (XSS), data manipulation, or remote code execution, depending on the context.
You are affected if you are using a version that falls within the vulnerable range.
@aws-amplify/codegen-ui-react is vulnerable to Cross-site Scripting (XSS) in versions 2.1.0 - 2.20.2.
Upgrade the @aws-amplify/codegen-ui-react library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant