CVE-2025-64321
No sign of exploitation. No public exploitation artifact known so far.
A vulnerability in Salesforce Agentforce Vibes Extension before version 3.3.0 allows attackers to manipulate configuration files by injecting malicious prompts that aren't properly validated. This could let an attacker modify settings or behavior of the extension without proper authorization.
The vulnerability exists in the input sanitization layer for LLM prompts within Agentforce Vibes Extension; an attacker can craft specially-formatted prompt input that bypasses neutralization controls to modify writeable configuration files. The attack requires the ability to provide input to the LLM prompt mechanism, and successful exploitation results in unauthorized modification of extension configuration.