Force.com Workbench Remote Code Execution Vulnerability via Malicious Cookie in Timezone Conversion

Vulnerability

A remote code execution vulnerability has been identified in Force.com Workbench versions prior to 65.0.0. The issue arises in the timezone conversion process, which improperly handles attacker-controlled cookie values, allowing for exploitation.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where Workbench is running.

Remediation

Users are advised to upgrade to Workbench version 65.0.0 or later. The vulnerability has been patched in this version by replacing deprecated functions with anonymous closures and adding input validation for cookie-based configuration values.

Added: Apr 6, 2026, 8:31 PM
Updated: Apr 6, 2026, 8:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.4
remediation
0.0
relevance
5.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.