Incomplete fix for CVE-2025-4318 code injection in Amazon...
UnratedCVE-2025-4318 · Published Jul 30, 2026 · updated Sep 22, 2026
Bulletin ID: 2026-066-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/30/2026 11:00 AM PDT Description: Amplify Codegen UI is a library that generates React components and themes from schema definitions for use in AWS Amplify projects. We identified CVE-2026-18245 , an issue that exists in the amplify-codgen-ui-react package that could allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process. Impacted versions: Resolution: This issue has been addressed in @aws-amplify/codegen-ui-react version 2.20.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There are no workarounds. Upgrade to version 2.20.6. Acknowledgements We would like to thank George Chen who reported this issue and collaborating on this issue through the coordinated issue disclosure process. References: GHSA-74xx-rjgf-m69j Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"patt...
Affected versions
Details and references
Bulletin ID: 2026-066-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/30/2026 11:00 AM PDT Description: Amplify Codegen UI is a library that generates React components and themes from schema definitions for use in AWS Amplify projects. We identified CVE-2026-18245 , an issue that exists in the amplify-codgen-ui-react package that could allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process. Impacted versions: Resolution: This issue has been addressed in @aws-amplify/codegen-ui-react version 2.20.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There are no workarounds. Upgrade to version 2.20.6. Acknowledgements We would like to thank George Chen who reported this issue and collaborating on this issue through the coordinated issue disclosure process. References: GHSA-74xx-rjgf-m69j Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-066-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react Bulletin ID: 2026-066-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/30/2026 11:00 AM PDT Description: Amplify Codegen UI is a library that generates React components and themes from schema definitions for use in AWS Amplify projects. We identified CVE-2026-18245 , an issue that exists in the amplify-codgen-ui-react package that could allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process. Impacted versions: Resolution: This issue has been addressed in @aws-amplify/codegen-ui-react version 2.20.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There are no workarounds. Upgrade to version 2.20.6. Acknowledgements We would like to thank George Chen who reported this issue and collaborating on this issue through the coordinated issue disclosure process. References: GHSA-74xx-rjgf-m69j Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. Veterans, military spouses, and people with disabilities are encouraged to apply.", "copyrightText": "© 2026, Amazon Web Services, Inc. or its affiliates. All rights reserved.", "items": [ { "name": "Learn", "linkURL": "", "items": [ { "heading": "What Is AWS?", "linkURL": "/what-is-aws/?nc1=f_cc" }, { "heading": "What Is Cloud Computing?", "linkURL": "/what-is-cloud-computing/?nc1=f_cc" }, { "heading": "What Is Agentic AI?", "linkURL": "/what-is/agentic-ai/?nc1=f_cc" }, { "heading": "Cloud Computing Concept
- Severity from
- no source yet
- Also known as
- CVE-2026-18245
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | AWS: code execution | Unrated | No fix yet |
| Aug 4 | Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation | Unrated | No fix yet |
| Aug 3 | Disabled SSH host key verification in AWS CLI EMR helper commands | Unrated | No fix yet |
| Aug 3 | Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt... | Unrated | No fix yet |
| Jul 31 | Incorrect authorization in Strands Agents Tools http_request tool | Unrated | No fix yet |
| Jul 31 | Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft | Unrated | No fix yet |