What the vulnerability does

01Description

Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6.

Key dates

02Disclosure timeline

September 23, 2025 CVE published
February 26, 2026 Record updated