CVE-2025-4318: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in Amazon Amplify Studio
The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
AI Analysis
Technical Summary
This vulnerability (CWE-95) in AWS Amplify Studio's UI component property expressions allows insufficient input validation, enabling authenticated users with limited privileges to inject and execute arbitrary JavaScript code during the component rendering and build process. This can lead to high-impact consequences due to the execution of malicious code within the Amplify Studio environment. The vulnerability affects version 0.1.0 of the aws-amplify/amplify-codegen-ui package. AWS, as the cloud service provider, manages the remediation and has released an official fix.
Potential Impact
An authenticated user with permissions to create or modify components can exploit this vulnerability to execute arbitrary JavaScript code during component rendering and build. This can compromise the integrity and security of the build process, potentially leading to unauthorized actions or code execution within the Amplify Studio environment. The vulnerability is rated critical with a CVSS 4.0 score of 9, reflecting high attack vector, complexity, and impact metrics.
Mitigation Recommendations
AWS manages remediation for this cloud-hosted service and has released an official fix. Users should refer to the AWS security bulletin (https://aws.amazon.com/security/security-bulletins/AWS-2025-010/) for detailed guidance and ensure their Amplify Studio environment is updated accordingly. No additional user action is required beyond applying the vendor's fix or updates as managed by AWS.
CVE-2025-4318: CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in Amazon Amplify Studio
Description
The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
CVSS v4.0
Score 9.0critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-95) in AWS Amplify Studio's UI component property expressions allows insufficient input validation, enabling authenticated users with limited privileges to inject and execute arbitrary JavaScript code during the component rendering and build process. This can lead to high-impact consequences due to the execution of malicious code within the Amplify Studio environment. The vulnerability affects version 0.1.0 of the aws-amplify/amplify-codegen-ui package. AWS, as the cloud service provider, manages the remediation and has released an official fix.
Potential Impact
An authenticated user with permissions to create or modify components can exploit this vulnerability to execute arbitrary JavaScript code during component rendering and build. This can compromise the integrity and security of the build process, potentially leading to unauthorized actions or code execution within the Amplify Studio environment. The vulnerability is rated critical with a CVSS 4.0 score of 9, reflecting high attack vector, complexity, and impact metrics.
Mitigation Recommendations
AWS manages remediation for this cloud-hosted service and has released an official fix. Users should refer to the AWS security bulletin (https://aws.amazon.com/security/security-bulletins/AWS-2025-010/) for detailed guidance and ensure their Amplify Studio environment is updated accordingly. No additional user action is required beyond applying the vendor's fix or updates as managed by AWS.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- AMZN
- Date Reserved
- 2025-05-05T14:03:53.695Z
- Cisa Enriched
- true
- Cvss Version
- 4.0
- State
- PUBLISHED
- Is Cloud Service
- true
- Vendor Advisory Urls
- [{"url":"https://aws.amazon.com/security/security-bulletins/AWS-2025-010/","vendor":"AWS"}]
Threat ID: 682d981dc4522896dcbdae87
Added to database: 05/21/2025, 09:08:45 UTC
Last enriched: 07/29/2026, 21:21:54 UTC
Last updated: 08/02/2026, 00:12:02 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.