Input validation issue in AWS Amplify Studio UI component properties
Summary
| CVE | CVE-2025-4318 |
|---|---|
| State | PUBLISHED |
| Assigner | AMZN |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-05-05 19:15:57 UTC |
| Updated | 2026-07-29 16:17:47 UTC |
| Description | The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process. |
Risk And Classification
Primary CVSS: v4.0 9 CRITICAL from ff89ba41-3aa1-4d27-914a-91399e9639e5
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.009230000 probability, percentile 0.568470000 (date 2026-07-30)
Problem Types: CWE-95 | CWE-95 CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | Secondary | 9 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 9 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
LowUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Amazon | Amplify Studio | affected 0.1.0 2.20.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| aws.amazon.com/security/security-bulletins/AWS-2025-010 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | aws.amazon.com | |
| blog.securelayer7.net/cve-2025-4318-aws-amplify-rce | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | blog.securelayer7.net | |
| github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.3 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | github.com | |
| github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f... | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-... | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.