<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:42:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342411</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342411</link>
      <description>EUVD-2026-342411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342411</guid>
    </item>
    <item>
      <title>fkie_cve-2025-4318</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4318</link>
      <description>&lt;p&gt;The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code during the component rendering and build process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-4318</guid>
    </item>
    <item>
      <title>GHSA-hf3j-86p7-mfw8 — AWS Amplify Studio UI Component Properties Has an Input Validation Issue</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hf3j-86p7-mfw8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @aws-amplify/codegen-ui-react&lt;/p&gt;
&lt;p&gt;### Summary
The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-amplify/amplify-codegen-ui) is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating component files in customers&amp;#39; local applications.&lt;/p&gt;
&lt;p&gt;An issue exists in the Amplify Studio property binding process of the `amplify-codegen-ui `package that could potentially allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process.&lt;/p&gt;
&lt;p&gt;### Impact
When importing a component schema using the [create-component](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/amplifyuibuilder/create-component.html) command, Amplify Studio will import and generate the component on the users&amp;#39; behalf. The expression-binding function does not validate the component schema properties before converting them to expressions. As a result, an authenticated user who can create or modify components could run arbitrary JavaScript code during the component rendering and build process.&lt;/p&gt;
&lt;p&gt;**Impacted versions: &amp;lt;=2.20.2**&lt;/p&gt;
&lt;p&gt;### Patches
This issue has been addressed partially in version [2.20.3](https://github.com/aws-amplify/amplify-codegen-ui/pull/1174) and additional fixes in [2.20.4](https://github.com/aws-amplify/amplify-codegen-ui/pull/1196). We recommend upgrading to the latest version and ensuring any forked or de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @aws-amplify/codegen-ui-react&lt;/p&gt;
&lt;p&gt;### Summary
The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-amplify/amplify-codegen-ui) is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating component files in customers&amp;#39; local applications.&lt;/p&gt;
&lt;p&gt;An issue exists in the Amplify Studio property binding process of the `amplify-codegen-ui `package that could potentially allow an authenticated user to run arbitrary JavaScript code during the component rendering and build process.&lt;/p&gt;
&lt;p&gt;### Impact
When importing a component schema using the [create-component](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/amplifyuibuilder/create-component.html) command, Amplify Studio will import and generate the component on the users&amp;#39; behalf. The expression-binding function does not validate the component schema properties before converting them to expressions. As a result, an authenticated user who can create or modify components could run arbitrary JavaScript code during the component rendering and build process.&lt;/p&gt;
&lt;p&gt;**Impacted versions: &amp;lt;=2.20.2**&lt;/p&gt;
&lt;p&gt;### Patches
This issue has been addressed partially in version [2.20.3](https://github.com/aws-amplify/amplify-codegen-ui/pull/1174) and additional fixes in [2.20.4](https://github.com/aws-amplify/amplify-codegen-ui/pull/1196). We recommend upgrading to the latest version and ensuring any forked or de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hf3j-86p7-mfw8</guid>
    </item>
  </channel>
</rss>
