CVE-2025-64320: Code Injection
Published Nov 4, 2025
·Updated
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.
Affected Software
2 affected components
Salesforce Agentforce Vibes Extension<3.2.0
Salesforce Agentforce Vibes Visual Studio Code<3.2.0
Event History
Nov 4, 2025
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64320?
CVE-2025-64320 has been classified as a high-severity vulnerability.
2
How do I fix CVE-2025-64320?
To mitigate CVE-2025-64320, upgrade the Salesforce Agentforce Vibes Extension to version 3.2.0 or later.
3
What systems are affected by CVE-2025-64320?
CVE-2025-64320 affects the Salesforce Agentforce Vibes Extension versions prior to 3.2.0.
4
What type of vulnerability is CVE-2025-64320?
CVE-2025-64320 is an improper neutralization of input used for LLM prompting vulnerability allowing code injection.
5
Is there a workaround for CVE-2025-64320?
There are currently no known workarounds for CVE-2025-64320 besides upgrading to a fixed version.