CVE-2025-64320
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.20%
- CWE
- CWE-1427
- Published
- 2025-11-04
- Last modified
- 2026-03-12
Affected products
- Salesforce Agentforce Vibes Extension
Weakness type
Related vulnerabilities
- CVE-2026-70331 — Microsoft Edge for iOS Spoofing Vulnerability
- CVE-2026-78379 — Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools
- CVE-2026-75130 — Context7 2.1.2 Prompt Injection via Custom AI Instructions
- CVE-2026-21832 — HCL AION is affected by multiple security vulnerabilities.
- CVE-2026-18733 — Prompt injection bypasses shell tool consent gate in Strands Agents Tools
- CVE-2026-15077 — Improper Neutralization of Input Used for LLM Prompting in GitLab
- CVE-2026-46580 — In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in...
- CVE-2026-44688 — In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory...