CVE-2025-4318
AWS Amplify Studio UI Component Property Injection Vulnerability
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
A vulnerability exists in AWS Amplify Studio's UI component property handling, potentially allowing authenticated users to execute arbitrary JavaScript code during build processes. This impacts the security of developer tools and the software supply chain, requiring confirmation of internal exposure.