Intel

AIKIDO-2025-10233

@aws-amplify/codegen-ui-react is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-4318

95

Critical Risk

This Affects:

JS@aws-amplify/codegen-ui-react
2.1.0 - 2.20.2
Fixed in 2.20.3

TL;DR

Affected versions of this package fail to properly sanitize expression bindings when recursively rendering collection-type components, allowing malicious input to be processed unsafely. An attacker can craft a malicious component with injected expressions or scripts, which Amplify Studio will render without sanitization, potentially leading to cross-site scripting (XSS), data manipulation, or remote code execution, depending on the context.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@aws-amplify/codegen-ui-react is vulnerable to Cross-site Scripting (XSS) in versions 2.1.0 - 2.20.2.

How to fix this

Upgrade the @aws-amplify/codegen-ui-react library to the patch version.