CVE-2026-18245
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedImproper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318. To remediate this issue, users should upgrade to version 2.20.6
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceImproper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 allows authenticated users to inject arbitrary code through crafted Studio component or theme schema values. This is a bypass of CVE-2025-4318, where input validation coverage and effectiveness were insufficient, enabling code execution in end-user browsers, developer machines, CI/CD pipelines, and SSR contexts.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 2.20.6CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Check installed @aws-amplify/codegen-ui-react versionRun 'npm list @aws-amplify/codegen-ui-react' or inspect the version in package.json under dependencies or devDependenciesAffected if The installed version is lower than 2.20.6
-
Verify codegen command usageCheck if your project runs 'amplify codegen' or uses the codegen API to generate UI code from Studio component or theme schemasAffected if Your project uses codegen to process Studio component or theme schema files (typically .json schema files from Amplify Studio)
-
Identify schema input sourcesReview your project for Studio component schema files (usually in amplify/backend/api/*/schema.graphql or custom component schema .json files) and theme schema .json files processed by codegenAffected if You have custom or imported Studio component schemas or theme schemas that are fed into the codegen process
You are affected if @aws-amplify/codegen-ui-react version is below 2.20.6 AND your project processes Studio component or theme schemas through codegen, as crafted malicious schema values could trigger arbitrary code execution during code generation.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped2.20.6
Upgrade @aws-amplify/codegen-ui-react to version 2.20.6 or later to obtain the improved input validation that addresses this code injection vulnerability.
2.20.6
- Update the @aws-amplify/codegen-ui-react package to version 2.20.6 or later
- Run npm install @aws-amplify/[email protected] or yarn add @aws-amplify/[email protected] to install the fixed version
- Rebuild and redeploy any applications using this package to ensure the fix is applied
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation6.0 h
- Implementation4.0 h
- Testing12.0 h
- Review / QA6.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $7,680.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-18245 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-18245 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data