Initially JavaScript was being escaped with their WAF.
The second POC demonstrated the ability to evade both their WAF and XSS_Auditor.
Their development team then verified the ability to execute arbitrary JavaScript from any *.cloudfront.net host.
That's pretty much the whole story.