# Salesforce Agentforce SalesBleed vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/salesforce-agentforce-salesbleed-vulnerabilities
> Updated: 2026-09-27T02:05:03.000Z. Sources: 3. Developments: 2.

Security researchers at Zenity Labs identified a series of vulnerabilities in Salesforce Agentforce, collectively named ‘SalesBleed’. These flaws enabled zero-click data exfiltration and phishing attacks by exploiting how AI agents interact with data from Web-to-Lead forms.

Attackers could plant malicious instructions via public forms that remained dormant until an internal user prompted the agent to process the submission. Once triggered, the agent could be manipulated into querying sensitive CRM data, such as accounts and leads tables. The data could then be exfiltrated to attacker-controlled servers via DNS queries triggered by image rendering or through the Agentforce-Slack integration using automated link previews.

Specific weaknesses were found in the ‘Trusted URLs’ security mechanism, which failed to properly handle certain character sequences or recognize specific top-level domains during URL parsing. Salesforce has since patched these vulnerabilities.

## Timeline

### 2026-09-27: Salesforce Agentforce vulnerabilities dubbed SalesBleed enable zero-click attacks

Zenity Labs discovered ‘SalesBleed’, three vulnerabilities in Salesforce Agentforce allowing zero-click data exfiltration and phishing via poisoned Web-to-Lead forms. All flaws have been patched.

2 sources. https://clstr.news/cluster/salesforce-agentforce-vulnerabilities-dubbed-salesbleed-enable-zero-click-attacks

### 2026-09-24: Salesforce Agentforce vulnerabilities allow zero-click data theft

Researchers discovered ‘SalesBleed’ vulnerabilities in Salesforce Agentforce, which allowed attackers to use indirect prompt injection to steal CRM data via zero-click DNS exfiltration.

2 sources. https://clstr.news/cluster/salesforce-agentforce-vulnerabilities-allow-zero-click-data-theft

---
Cite as: Salesforce Agentforce SalesBleed vulnerabilities. CLSTR, https://clstr.news/situations/salesforce-agentforce-salesbleed-vulnerabilities
