Description

Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and below allow a maliciously crafted flow metadata file to cause arbitrary JavaScript execution during scanning. The APIVersion rule uses new Function() to evaluate expression strings, enabling an attacker to supply a malicious expression within rule configuration or crafted flow metadata. This could compromise developer machines, CI runners, or editor environments. This issue is fixed in version 6.10.6.

INFO

Published Date :

2025-12-12T20:14:21.004Z

Last Modified :

2025-12-12T20:50:57.161Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-67750 vulnerability.

Vendors Products
Flow-scanner
  • Lightning-flow-scanner

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact