« Back to list

CVE-2025-4318

Status: DeferredCritical (9)—

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Acceso remoto con PR:L (autenticado) en servicio de compilación UI. Ejecución de JavaScript arbitrario en el proceso de construcción de componentes, con potencial manipulación de artefactos.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (2)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-4318",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-4318",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-18T16:07:11.415601Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 9,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "HIGH",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "HIGH",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "HIGH",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
      "affectedData": [
        {
          "vendor": "Amazon",
          "product": "Amplify Studio",
          "versions": [
            {
              "status": "affected",
              "version": "0.1.0",
              "lessThan": "2.20.3",
              "versionType": "semver"
            }
          ],
          "packageName": "amplify-codegen-ui",
          "collectionURL": "https://github.com/aws-amplify/amplify-codegen-ui",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-05T19:15:57.847",
  "references": [
    {
      "url": "https://aws.amazon.com/security/security-bulletins/AWS-2025-010/",
      "source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
    },
    {
      "url": "https://github.com/aws-amplify/amplify-codegen-ui/releases/tag/v2.20.3",
      "source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
    },
    {
      "url": "https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8",
      "source": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
    },
    {
      "url": "https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce/",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
      "description": [
        {
          "lang": "en",
          "value": "CWE-95"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process."
    },
    {
      "lang": "es",
      "value": "Las expresiones de propiedad del componente de interfaz de usuario de AWS Amplify Studio en el paquete aws-amplify/amplify-codegen-ui carecen de validación de entrada. Esto podría permitir que un usuario autenticado con acceso para crear o modificar componentes ejecute código JavaScript arbitrario durante el proceso de renderizado y compilación de componentes."
    }
  ],
  "lastModified": "2026-07-29T16:17:47.997",
  "sourceIdentifier": "ff89ba41-3aa1-4d27-914a-91399e9639e5"
}