@aws-amplify/codegen-ui-react is vulnerable to Cross-site Scripting (XSS)
95
Critical Risk
Affected versions of this package fail to properly sanitize expression bindings when recursively rendering collection-type components, allowing malicious input to be processed unsafely. An attacker can craft a malicious component with injected expressions or scripts, which Amplify Studio will render without sanitization, potentially leading to cross-site scripting (XSS), data manipulation, or remote code execution, depending on the context.
You are affected if you are using a version that falls within the vulnerable range.
@aws-amplify/codegen-ui-react is vulnerable to Cross-site Scripting (XSS) in versions 2.1.0 - 2.20.2.
Upgrade the @aws-amplify/codegen-ui-react library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant