🔐 CVE Alert

CVE-2026-18245

CRITICAL 9.0

Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

CVSS Score
9.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318. To remediate this issue, users should upgrade to version 2.20.6

CWE CWE-94
Vendor aws
Product amplify codegen ui
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for aws amplify codegen ui

Be the first to know when new critical vulnerabilities affecting aws amplify codegen ui are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

AWS / Amplify Codegen UI
0 < 2.20.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.6 aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-066-aws/ github.com: https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-74xx-rjgf-m69j