To remediate this issue, users should upgrade to versionĀ 2.20.6
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318. To remediate this issue, users should upgrade to versionĀ 2.20.6 | |
| Title | Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react | |
| First Time appeared |
Aws
Aws amplify Codegen Ui |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:aws:amplify_codegen_ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws amplify Codegen Ui |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-30T18:14:32.806Z
Reserved: 2026-07-29T14:45:04.539Z
Link: CVE-2026-18245
No data.
No data.
No data.
OpenCVE Enrichment
No data.