< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Salesforce Agentforce vulnerabilities dubbed SalesBleed enable zero-click attacks

Security researchers at Zenity Labs have disclosed ‘SalesBleed’, a series of three vulnerabilities in Salesforce Agentforce that could allow attackers to perform zero-click data exfiltration and phishing attacks.

The flaws exploit the way AI agents interact with data from Web-to-Lead forms. An attacker can submit a poisoned lead containing malicious instructions that remain dormant until an employee asks the Agentforce agent to process the submission. Once triggered, the agent can be manipulated into querying sensitive CRM data, such as accounts and leads tables, and transmitting that information to an attacker-controlled server.

Two of the vulnerabilities stem from weaknesses in the ‘Trusted URLs’ security mechanism, which failed to properly recognize certain top-level domains or handle character sequences during URL parsing. This allowed sensitive data to be embedded in HTML image tags and exfiltrated via DNS queries without user interaction. A third vulnerability involves the Agentforce-Slack integration, which could be weaponized to distribute phishing messages through automated link previews. Salesforce has since patched these vulnerabilities.

Entities

Agentforce · Salesforce · Slack · Zenity Labs