CRITICAL GitHub
CVE-2025-4318
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
### Summary
The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-amplify/amplify-codegen-ui) is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating component files in customers' local applications.
An issue exists in the Amplify Studio property binding process of the `amplify-codegen-ui `package that could potent
Affected Products
- npm/@aws-amplify/codegen-ui-react <= 2.20.2
References
- https://github.com/advisories/GHSA-hf3j-86p7-mfw8
- https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8
- https://nvd.nist.gov/vuln/detail/CVE-2025-4318
- https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8
This critical severity vulnerability was published on 2026-07-30 via GitHub. Affected: npm/@aws-amplify/codegen-ui-react <= 2.20.2.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.