CVE-2026-18245: Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318.
To remediate this issue, users should upgrade to version 2.20.6
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18245?
The severity of CVE-2026-18245 is rated as critical with a score of 9.
How do I fix CVE-2026-18245?
To fix CVE-2026-18245, update to the latest version of @aws-amplify/codegen-ui-react, specifically version 2.20.6 or later.
What types of vulnerabilities are associated with CVE-2026-18245?
CVE-2026-18245 is associated with code injection and improper input validation.
What impact does CVE-2026-18245 have on systems?
CVE-2026-18245 can allow a remote authenticated user to execute arbitrary code in various environments including end-user browsers and CI/CD setups.
When was CVE-2026-18245 published?
CVE-2026-18245 was published on July 30, 2026.