Junglewise Threat Intelligence

CVE-2025-4318: AWS Amplify Studio eval injection in amplify-codegen-ui

CVE-2025-4318 · Severity: critical · CVSS 9 · Published 2026-07-30

Executive brief

Amazon's @aws-amplify/codegen-ui-react is a code generation tool used by developers to automatically generate React UI components. An incomplete security fix for a prior code injection vulnerability (CVE-2025-4318) means attackers could still inject and execute arbitrary code during the code generation process, potentially compromising applications built with this tool.

Technical details

The vulnerability is a code injection flaw in Amazon @aws-amplify/codegen-ui-react that was previously identified as CVE-2025-4318. The original patch was incomplete, leaving the code generation process still vulnerable to malicious input injection. An attacker who can control input to the code generation process (such as through manipulated design files or configuration) can inject arbitrary code that gets embedded into the generated React component code. This allows arbitrary code execution in the context of applications using the generated components. The fix status and available patches should be verified through AWS security bulletins.

Affected products

  • Amazon @aws-amplify/codegen-ui-react

Timeline

  • 2026-09-22: disclosed

References

Related threats