CVE-2025-64320 Details
Description
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.
A code injection vulnerability has been identified in the Salesforce Agentforce Vibes Extension, affecting versions prior to 3.2.0. This vulnerability arises from improper neutralization of input used for large language model (LLM) prompting, which could allow arbitrary command execution. When combined with prompt injection, it could lead to remote code execution, potentially granting full access to the victim's Salesforce organization.
Users of the Agentforce Vibes extension should update to version 3.2.0 or later. Those who have disabled automatic updates must manually check for and install the latest version. Instructions for manually updating extensions are available in the Salesforce Knowledge Article Number 005228032.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.salesforce.com/s/articleView?id=005228032&type=1 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| salesforce agentforce vibes | < 3.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 4, 2026 | Initial Analysis | [email protected] |
| Nov 4, 2025 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | New CVE Received | [email protected] |