Salesforce Agentforce Flaws Allow Zero-Click Data Exfiltration and Phishing Attacks
A trio of vulnerabilities in Salesforce’s Agentforce platform has been discovered to enable attackers to hijack trusted agents for sensitive customer relationship management (CRM) data exfiltration and phishing attacks. Dubbed “SalesBleed,” the flaws could be exploited via Web-to-Lead forms, a mechanism used by Salesforce to collect leads from external sources.
The vulnerabilities, identified by Zenity Labs, allow malicious instructions to be injected into a Web-to-Lead form, which remain dormant until an employee interacts with the submission. At that point, the agent is prompted to process the poisoned lead and execute the hidden instructions. Two of the SalesBleed bugs can be exploited in zero-click data exfiltration attacks, while the third allows attackers to weaponize an Agentforce agent to distribute phishing messages.
The first two flaws were caused by weaknesses in Trusted URLs, a security mechanism designed to block Agentforce from displaying URLs and images from untrusted sources. However, Zenity Labs discovered that this mechanism failed to recognize top-level domains and was vulnerable to character sequences that could tamper with URL parsing.
Using the same poisoned Web-to-Lead mechanism, an attacker can interact with the Agentforce agent via Slack, which automatically retrieves link information for previews. Specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as the links appear.
Furthermore, Zenity Labs discovered that Agentforce’s integration with Slack could be abused to turn the AI agents into a social-engineering mechanism and send messages to various internal Slack channels. This allows an attacker to hijack the agent and post phishing messages to Slack using the agent’s identity, making it difficult for employees to distinguish between legitimate and malicious messages.
The SalesBleed vulnerabilities were reported by Zenity Labs on June 1, and Salesforce confirmed that all three bugs had been addressed by August 19. While this is a welcome fix, it serves as a reminder of the importance of staying vigilant in today’s cybersecurity landscape.
For organizations using Agentforce or integrating with Salesforce, this vulnerability should be taken as a wake-up call to review their security measures and ensure that they are equipped to handle similar threats. This includes implementing robust security protocols for Web-to-Lead forms and Trusted URLs, as well as educating employees on the dangers of phishing attacks and how to identify suspicious messages.
Ultimately, the SalesBleed vulnerabilities highlight the need for continuous monitoring and improvement in cybersecurity practices. By staying informed about emerging threats and taking proactive steps to protect against them, organizations can reduce their risk exposure and safeguard sensitive data.
Source: SecurityWeek — 2026-09-25