CVE-2025-64321

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesforce:agentforce_vibes:*:*:*:*:*:visual_studio_code:*:*

History

04 Feb 2026, 19:51

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de la entrada utilizada para el prompting de LLM en la Extensión Salesforce Agentforce Vibes permite manipular archivos de configuración escribibles. Este problema afecta a la Extensión Agentforce Vibes: antes de la 3.2.0.
References () https://help.salesforce.com/s/articleView?id=005228032&type=1 - () https://help.salesforce.com/s/articleView?id=005228032&type=1 - Vendor Advisory
First Time Salesforce
Salesforce agentforce Vibes
CWE CWE-94
CPE cpe:2.3:a:salesforce:agentforce_vibes:*:*:*:*:*:visual_studio_code:*:*

11 Nov 2025, 05:16

Type Values Removed Values Added
Summary (en) Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.2.0. (en) Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.

04 Nov 2025, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

04 Nov 2025, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 19:17

Updated : 2026-02-04 19:51


NVD link : CVE-2025-64321

Mitre link : CVE-2025-64321

CVE.ORG link : CVE-2025-64321


JSON object : View

Products Affected

salesforce

  • agentforce_vibes
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')