What is CVE-2026-18245?
A vulnerability in Amazon @aws-amplify/codegen-ui-react (before version 2.20.6) involves improper control of code generation, which could allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via a crafted Studio component or theme schema. Updating the library to version 2.20.6 or later is strongly advised.
Azərbaycanca: Amazon @aws-amplify/codegen-ui-react kitabxanasında (2.20.6-dan əvvəlki versiyalarda) kod generasiyasına düzgün nəzarət edilməməsi zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş uzaq istifadəçiyə xüsusi hazırlanmış Studio komponent və ya tema sxemi ilə son istifadəçi brauzerlərində, tərtibatçı maşınlarında, CI/CD mühitlərində və server tərəfli render kontekstlərində ixtiyari kod icra etməyə imkan verə bilər. Kitabxananı ən az 2.20.6 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Does exploiting CVE-2026-18245 in the @aws-amplify/codegen-ui-react library require the attacker to be authenticated?
Yes, exploiting this vulnerability requires the attacker to be a remote authenticated user.
To which version should the library be updated to remediate CVE-2026-18245?
Updating the library to version 2.20.6 or later is strongly advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.