CVE-2025-4318
The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 9
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.98%
- Percentile among all scored CVEs: 61
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement75 % - Primary impact
T1059Command and Scripting Interpreterexecution85 % - Secondary impact
T1565Data Manipulationimpact60 %
Acceso remoto con PR:L (autenticado) en servicio de compilación UI. Ejecución de JavaScript arbitrario en el proceso de construcción de componentes, con potencial manipulación de artefactos.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (2)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-95
References
- https://aws.amazon.com/security/security-bulletins/AWS-2025-010/
- https://github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.3
- https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8
- https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/
- https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6
- https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8
- https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/
Raw JSON (NVD)
Show
{
"id": "CVE-2025-4318",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-4318",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-07-18T16:07:11.415601Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "LOW",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"affectedData": [
{
"vendor": "Amazon",
"product": "Amplify Studio",
"versions": [
{
"status": "affected",
"version": "0.1.0",
"lessThan": "2.20.3",
"versionType": "semver"
}
],
"packageName": "amplify-codegen-ui",
"collectionURL": "https://github.com/aws-amplify/amplify-codegen-ui",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-05T19:15:57.847",
"references": [
{
"url": "https://aws.amazon.com/security/security-bulletins/AWS-2025-010/",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.3",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
},
{
"url": "https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"description": [
{
"lang": "en",
"value": "CWE-95"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process."
},
{
"lang": "es",
"value": "Las expresiones de propiedad del componente de interfaz de usuario de AWS Amplify Studio en el paquete aws-amplify/amplify-codegen-ui carecen de validación de entrada. Esto podría permitir que un usuario autenticado con acceso para crear o modificar componentes ejecute código JavaScript arbitrario durante el proceso de renderizado y compilación de componentes."
}
],
"lastModified": "2026-07-29T16:17:47.997",
"sourceIdentifier": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
}