Amazon @aws-amplify/codegen-ui-react: Incomplete Fix for Code Injection Flaw
Amazon @aws-amplify/codegen-ui-react has an incomplete patch for CVE-2025-4318, a code injection vulnerability. User action is required—check AWS Security Bulletins for the latest details and apply available fixes. This affects your build pipeline if you're using this code generation tool.
source: [aws/security-bulletin]