CVE-2025-67750
HIGHlightning-flow-scanner < 6.10.6 - Remote Code Execution via Malicious Flow Metadata
Title source: llmDescription
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and below allow a maliciously crafted flow metadata file to cause arbitrary JavaScript execution during scanning. The APIVersion rule uses new Function() to evaluate expression strings, enabling an attacker to supply a malicious expression within rule configuration or crafted flow metadata. This could compromise developer machines, CI runners, or editor environments. This issue is fixed in version 6.10.6.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/Flow-Scanner/lightning-flow-scanner/security/advisories/GHSA-55jh-84jv-8mx8
Patch x_refsource_misc
https://github.com/Flow-Scanner/lightning-flow-scanner/commit/10f64a5eb193d8a777e453b25e910144e4540795
Release Notes x_refsource_misc
https://github.com/Flow-Scanner/lightning-flow-scanner/releases/tag/core-v6.10.6
Scores
CVSS v3
8.4
EPSS
0.0002
EPSS Percentile
6.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (2)
Flow-Scanner/lightning-flow-scanner
< 6.10.6
npm/lightning-flow-scanner
0 - 6.10.6npm
Published
Dec 12, 2025
Tracked Since
Feb 18, 2026