Critical AWS Amplify Studio Flaw Allowed Attackers to Execute Arbitrary Code

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

Critical AWS Amplify Studio Flaw Allowed Attackers to Execute Arbitrary Code

Post by Shane1145 »

Amazon Web Services (AWS) has addressed a critical security flaw (CVE-2025-4318) in its AWS Amplify Studio platform, which could have allowed authenticated attackers to execute malicious JavaScript code during component rendering.

The vulnerability, publicly disclosed on May 5, 2025, affects the amplify-codegen-ui package, a core tool for generating front-end code in Amplify Studio.


https://gbhackers.com/critical-aws-amplify-studio-flaw/
Post Reply