Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
Bulletin ID: 2026-066-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/30/2026 11:00 AM PDT
Description:
Amplify Codegen UI is a library that generates React components and themes from schema definitions for use in AWS Amplify projects. We identified CVE-2026-18245, an issue that exists in the amplify-codgen-ui-react package that could allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process.
Impacted versions: <2.20.6
Resolution:
This issue has been addressed in @aws-amplify/codegen-ui-react version 2.20.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There are no workarounds. Upgrade to version 2.20.6.
Acknowledgements
We would like to thank George Chen who reported this issue and collaborating on this issue through the coordinated issue disclosure process.
References:
Please email aws-security@amazon.com with any security questions or concerns.