Intel

AIKIDO-2026-947943

@aws-amplify/codegen-ui-react is vulnerable to Code Injection

Code InjectionCVE-2026-18245 Published 2 days ago

90

Critical Risk

This Affects:

JS@aws-amplify/codegen-ui-react
1.0.0 - 2.20.5
Fixed in 2.20.6
Are you affected? Scan for Free

TL;DR

Improper control of code generation in @aws-amplify/codegen-ui-react before 2.20.6 could allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you generate React components or themes from Studio component or theme schema values that can be influenced by untrusted users.

Background info

@aws-amplify/codegen-ui-react is vulnerable to Code Injection in versions 1.0.0 - 2.20.5.

How to fix this

Upgrade the @aws-amplify/codegen-ui-react library to the patch version.