CVE-2025-64320

CVE-2025-64320

Vendor Salesforce
Product Agentforce Vibes Extension
Weakness CWE-1427
Published November 4, 2025
Last update November 5, 2025

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.

Key dates

02Disclosure timeline

November 4, 2025 CVE published
November 5, 2025 Record updated