CVE-2025-10875: Code Injection
Published Nov 4, 2025
·Updated
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6.
Affected Software
2 affected components
Salesforce Mulesoft Anypoint Code Builder<1.11.6
Salesforce Mulesoft Anypoint Code Builder<1.11.6
Event History
Nov 4, 2025
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10875?
CVE-2025-10875 is classified with a high severity due to the possibility of code injection.
2
How do I fix CVE-2025-10875?
To fix CVE-2025-10875, upgrade Mulesoft Anypoint Code Builder to version 1.11.6 or later.
3
Which versions of Mulesoft Anypoint Code Builder are affected by CVE-2025-10875?
Versions prior to 1.11.6 of Mulesoft Anypoint Code Builder are affected by CVE-2025-10875.
4
What type of vulnerability is CVE-2025-10875?
CVE-2025-10875 is an improper neutralization of input used for LLM prompting vulnerability.
5
What can happen if CVE-2025-10875 is exploited?
Exploitation of CVE-2025-10875 may allow an attacker to perform code injection attacks.