Incomplete Fix: CVE-2025-4318 AWS Amplify Code Injection
🟠High | Source: AWS Security Bulletins An incomplete fix has been identified for CVE-2025-4318, a code injection vulnerability in Amazon’s @aws-amplify/codegen-ui-react library, which is used to auto-generate React UI components from Amplify Studio data models. The original patch did not fully remediate the vulnerability, meaning applications relying on the earlier fix may still be exposed to arbitrary code execution risks. Developers using this package should review the updated AWS Security Bulletin and apply the latest remediation immediately. ...