CVE-2025-64318

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesforce:mulesoft_anypoint_code_builder:*:*:*:*:*:*:*:*

History

04 Feb 2026, 20:02

Type Values Removed Values Added
First Time Salesforce
Salesforce mulesoft Anypoint Code Builder
References () https://help.salesforce.com/s/articleView?id=005228032&type=1 - () https://help.salesforce.com/s/articleView?id=005228032&type=1 - Vendor Advisory
CWE CWE-94
CPE cpe:2.3:a:salesforce:mulesoft_anypoint_code_builder:*:*:*:*:*:*:*:*
Summary
  • (es) La vulnerabilidad de neutralización inadecuada de la entrada utilizada para el prompting de LLM en Salesforce Mulesoft Anypoint Code Builder permite manipular archivos de configuración escribibles. Este problema afecta a Mulesoft Anypoint Code Builder: antes de la versión 1.11.6.

11 Nov 2025, 05:15

Type Values Removed Values Added
Summary (en) Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6. (en) Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1.

05 Nov 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.3

04 Nov 2025, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

04 Nov 2025, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 19:17

Updated : 2026-02-04 20:02


NVD link : CVE-2025-64318

Mitre link : CVE-2025-64318

CVE.ORG link : CVE-2025-64318


JSON object : View

Products Affected

salesforce

  • mulesoft_anypoint_code_builder
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')