CVE-2025-64318: Code Injection
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64318?
CVE-2025-64318 is classified as a high severity vulnerability due to its potential to manipulate writeable configuration files in Salesforce Mulesoft Anypoint Code Builder.
How do I fix CVE-2025-64318?
To remediate CVE-2025-64318, upgrade Salesforce Mulesoft Anypoint Code Builder to version 1.11.6 or later.
What versions of Salesforce Mulesoft Anypoint Code Builder are affected by CVE-2025-64318?
CVE-2025-64318 affects Salesforce Mulesoft Anypoint Code Builder versions prior to 1.11.6.
What type of vulnerability is CVE-2025-64318?
CVE-2025-64318 is an Improper Neutralization of Input Used for LLM Prompting vulnerability.
What could happen if CVE-2025-64318 is exploited?
Exploitation of CVE-2025-64318 could allow unauthorized manipulation of configuration files, potentially compromising the integrity of the application.