< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 3 sources · 3 days · First seen · Last updated

Salesforce Agentforce SalesBleed vulnerabilities

Overview

Security researchers at Zenity Labs identified a series of vulnerabilities in Salesforce Agentforce, collectively named ‘SalesBleed’. These flaws enabled zero-click data exfiltration and phishing attacks by exploiting how AI agents interact with data from Web-to-Lead forms.

Attackers could plant malicious instructions via public forms that remained dormant until an internal user prompted the agent to process the submission. Once triggered, the agent could be manipulated into querying sensitive CRM data, such as accounts and leads tables. The data could then be exfiltrated to attacker-controlled servers via DNS queries triggered by image rendering or through the Agentforce-Slack integration using automated link previews.

Specific weaknesses were found in the ‘Trusted URLs’ security mechanism, which failed to properly handle certain character sequences or recognize specific top-level domains during URL parsing. Salesforce has since patched these vulnerabilities.

Entities

Agentforce · Salesforce · Zenity Labs · Slack

Timeline

  1. [TECHNOLOGY] 2 sources
    Salesforce Agentforce vulnerabilities dubbed SalesBleed enable zero-click attacks

    Zenity Labs discovered ‘SalesBleed’, three vulnerabilities in Salesforce Agentforce allowing zero-click data exfiltration and phishing via poisoned Web-to-Lead forms. All flaws have been patched.

  2. [TECHNOLOGY] 2 sources
    Salesforce Agentforce vulnerabilities allow zero-click data theft

    Researchers discovered ‘SalesBleed’ vulnerabilities in Salesforce Agentforce, which allowed attackers to use indirect prompt injection to steal CRM data via zero-click DNS exfiltration.

Sources

cybernoz.com · dev.to · theregister.co.uk