The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @salesforce/cli to version 2.106.6 or higher.
@salesforce/cli is a The Salesforce CLI
Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the Replace Trusted Executable feature. An attacker can execute arbitrary code by placing a malicious executable in a directory that is searched before the intended trusted executable.
Note:
This vulnerability affects only those customers who downloaded the software from an untrusted source, rather than directly from the official Salesforce site. Untrusted downloads may contain a malicious file in the local directory, which could be executed instead of the legitimate files in the specified file path.