CVE-2025-64321: Code Injection
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64321?
CVE-2025-64321 has been classified as a high-risk vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2025-64321?
To fix CVE-2025-64321, update Salesforce Agentforce Vibes Extension to version 3.2.0 or higher.
What impacts does CVE-2025-64321 have on my system?
CVE-2025-64321 can allow unauthorized manipulation of writable configuration files, leading to potential data breaches.
Who is affected by CVE-2025-64321?
CVE-2025-64321 affects users of Salesforce Agentforce Vibes Extension versions prior to 3.2.0.
Can CVE-2025-64321 be exploited remotely?
Yes, CVE-2025-64321 can be exploited remotely if an attacker has access to the vulnerable version of the extension.