Security researchers at Zenity Labs reported three vulnerabilities in Salesforce Agentforce that could have enabled attackers to use poisoned Web-to-Lead submissions for CRM data exfiltration and phishing. SecurityWeek reports that Salesforce confirmed the issues were addressed by August 19 after receiving the report on June 1.

Two of the issues, collectively called SalesBleed, could support zero-click data exfiltration when an employee asked an Agentforce agent to interact with a poisoned lead. The reported path involved weaknesses in Trusted URLs, a mechanism intended to prevent the agent from displaying unapproved URLs and images. A third issue involved the Agentforce-Slack integration and could be used to send phishing messages under the identity of a trusted agent.

The research is a useful reminder that AI-agent integrations can turn ordinary data-ingestion workflows into prompt-injection boundaries. Security teams should review which external inputs agents can process, what data and tools agents can reach, and where downstream systems treat agent output as trusted.

Because Salesforce says the reported flaws were fixed, customers should validate their service configuration and relevant release status rather than assuming the research describes an unpatched current condition.

Source: SecurityWeek, “‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration”.

By Allan