Intel

AIKIDO-2026-947943

@aws-amplify/codegen-ui-react is vulnerable to Code Injection

Code InjectionCVE-2026-18245 Published Aug 5, 2026

90

Critical Risk

This Affects:

JS@aws-amplify/codegen-ui-react
1.0.0 - 2.20.5
Fixed in 2.20.6
Are you affected? Scan for Free

TL;DR

Improper control of code generation in @aws-amplify/codegen-ui-react before 2.20.6 could allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you generate React components or themes from Studio component or theme schema values that can be influenced by untrusted users.

Background info

@aws-amplify/codegen-ui-react is vulnerable to Code Injection in versions 1.0.0 - 2.20.5.

How to fix this

Upgrade the @aws-amplify/codegen-ui-react library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform