Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

Imported from official source

Security notice

Cybersecurity Classified by Officially

Amazon Web Services's source carried a headline and a link, and no summary. Officially records what a source published — for this item, that was all of it.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-066-aws/

Officially imported this from Amazon Web Services’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 22, 2026 20:12
Versions
2 recorded
Identity
3322af8ceb76cf1086856b2ed8940af29c6cddca

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.