< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Salesforce Agentforce vulnerabilities allow zero-click data theft

Security researchers at Zenity Labs have identified a series of vulnerabilities in Salesforce Agentforce, collectively named ‘SalesBleed’. These flaws allowed for indirect prompt injection and zero-click data exfiltration.

The attack chain began with an attacker using public Web-to-Lead forms to plant malicious instructions. When an internal user interacted with a standard lead query, the Agentforce sub-agent would follow the embedded prompts to retrieve sensitive account data. This data could then be exfiltrated via DNS queries triggered by image rendering or Slack link previews, requiring no additional clicks from the user.

Salesforce has since worked with security providers to patch these vulnerabilities. While the specific attack chains are no longer functional, researchers noted that the incident highlights the ongoing difficulty of containing AI agents and preventing them from bypassing intended security guardrails when encountering real-world data.

Entities

Agentforce · Salesforce · Zenity Labs