CVE-2025-9844: High severity Salesforce Salesforce CLI vulnerability
Published Sep 23, 2025
·Updated
Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6.
Affected Software
1 affected component
Salesforce Salesforce CLI<2.106.6
Event History
Sep 23, 2025
CVE Published
via MITRE·01:11 PM
Data Sourced
via MITRE·01:11 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Feb 28, 57989
Event
via FIRST·07:03 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9844?
CVE-2025-9844 is identified as a medium severity vulnerability due to its potential risk of executing untrusted code.
2
How do I fix CVE-2025-9844?
You can fix CVE-2025-9844 by updating Salesforce CLI to version 2.106.6 or later.
3
What specific issue does CVE-2025-9844 cause in Salesforce CLI?
CVE-2025-9844 allows for an Uncontrolled Search Path Element which can lead to unauthorized executable replacements.
4
Which versions of Salesforce CLI are affected by CVE-2025-9844?
CVE-2025-9844 affects Salesforce CLI versions prior to 2.106.6.
5
What type of systems are vulnerable to CVE-2025-9844?
CVE-2025-9844 specifically affects Windows operating systems running vulnerable versions of Salesforce CLI.