---
id: CVE-2025-4318
title: >-
  The AWS Amplify Studio UI component property expressions in the
  aws-amplify/amplify-codegen-ui package lack input validation
summary: >-
  The AWS Amplify Studio UI component property expressions in the
  aws-amplify/amplify-codegen-ui package lack input validation. This could
  potentially allow an authenticated user who has access to create or modify
  components to run arbitra…
severity: none
cwe:
  - CWE-95
published: '2025-05-05'
updated: '2026-07-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4318'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/AWS-2025-010/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.3'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00943
epssPercentile: 0.59343
ingestedAt: '2026-07-29T16:48:32.281Z'
---

## Overview

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
