The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 05 May 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process. | |
Title | Input validation issue in AWS Amplify Studio UI component properties | |
Weaknesses | CWE-95 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: AMZN
Published: 2025-05-05T18:16:34.075Z
Updated: 2025-05-05T18:56:01.694Z
Reserved: 2025-05-05T14:03:53.695Z
Link: CVE-2025-4318

Updated: 2025-05-05T18:55:57.729Z

Status : Awaiting Analysis
Published: 2025-05-05T19:15:57.847
Modified: 2025-05-05T20:54:19.760
Link: CVE-2025-4318

No data.