← back
CVE-2025-64318mediumCWE-1427

CVE-2025-64318

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
In short

A security flaw in Salesforce Mulesoft Anypoint Code Builder allows attackers to manipulate configuration files by injecting malicious commands into prompts. This could let unauthorized users alter system settings or gain control over application behavior.

Technical detail

Improper neutralization of LLM prompts (CWE-1427) in Mulesoft Anypoint Code Builder before 1.12.1 enables prompt injection attacks that permit modification of writable configuration files. The vulnerability requires user interaction with crafted prompts and allows attackers to alter critical application configurations.

Summary generated and translated by AI from the official description.
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N