@aws-amplify/codegen-ui-react is vulnerable to Code Injection
90
Critical Risk
Improper control of code generation in @aws-amplify/codegen-ui-react before 2.20.6 could allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318.
You are affected if you are using a version that falls within the vulnerable range and you generate React components or themes from Studio component or theme schema values that can be influenced by untrusted users.
@aws-amplify/codegen-ui-react is vulnerable to Code Injection in versions 1.0.0 - 2.20.5.
Upgrade the @aws-amplify/codegen-ui-react library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant