AWS Amplify Studio UI Component Properties Has an Input Validation Issue
- Severity:
- High
Description
The AWS Amplify Studio amplify-codegen-ui is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating component files in customers’ local applications.
Recommendation
Update the @aws-amplify/codegen-ui-react package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.20.2
- Patched version(s): 2.20.3
References
- GHSA-hf3j-86p7-mfw8
- aws.amazon.com
- blog.securelayer7.net
- CVE-2025-4318
- CWE-95
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component - CVE-2025-8082
- matrix-js-sdk has insufficient validation when considering a room to be upgraded by another - CVE-2025-59160
- validator.js has a URL validation bypass vulnerability in its isURL function - CVE-2025-56200
- Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - lodash-es - CVE-2025-13465
You might also like:
- Tags:
- npm
- @aws-amplify/codegen-ui-react
Anything's wrong? Let us know Last updated on July 30, 2026


