Salesforce Agents Exposed: “Salesbleed” Vulnerabilities Enable Phishing Attacks from Within Trusted Channels
A critical vulnerability in Salesforce Agentforce has been discovered, allowing attackers to phish employees from within trusted company channels. Dubbed “Salesbleed,” this exploit leverages weaknesses in Web-to-lead forms and AI-powered agents to smuggle arbitrary instructions across multiple apps into internal communications channels.
The issue stems from the way Salesforce’s powerful AI platforms process instructions. Researchers at Zenity found that an attacker can plant a specially crafted AI prompt in a Web-to-lead form, which is then ingested and executed by an Agentforce agent within the victim company’s environment. This allows attackers to exfiltrate data or even induce agents to perform actions such as replying to Slack threads on behalf of legitimate users.
The vulnerability is particularly concerning because it can be combined with normal Agentforce workflows to enable phishing attacks from within trusted channels. In a worst-case scenario, an attacker could use this exploit to inject malicious prompts into Web-to-lead forms, which would then be executed by agents and used to phish employees through Slack threads.
This is not the first time Salesforce has faced criticism over its AI-powered platform’s security. Last year, researchers at Noma Security revealed a way to steal corporate data using Salesforce’s Web-to-lead forms. While Salesforce responded quickly by implementing rules around URLs that attackers might use for malicious purposes, these measures failed to address the underlying issues with how Agentforce processes instructions.
The new findings from Zenity demonstrate that an attacker can simply work around these URL filtering rules and execute similar attacks using simple workarounds. The researchers highlighted the convenience of this exploit, noting that it’s impossible to identify or punish attackers who use Web-to-lead forms for malicious purposes.
To make matters worse, Salesforce agents have been granted permissions within Slack channels, allowing them to read and write data with ease. While users can configure agents to require user confirmation before performing actions, these controls are absent when it comes to an agent’s ability to reply to Slack threads. This oversight has left a gaping hole in the security of Agentforce.
The discovery of Salesbleed highlights the ongoing struggle to secure powerful AI platforms like Salesforce Agentforce. As more companies adopt these interconnected systems, it’s essential that developers prioritize robust security measures and visibility into how these agents process instructions.
For now, users of Salesforce Agentforce should exercise extreme caution when interacting with Web-to-lead forms or allowing agents to interact with Slack channels. To minimize the risk of falling victim to a Salesbleed-style attack, organizations should ensure that their agents are configured to require user confirmation for all actions and implement robust monitoring and detection capabilities to identify suspicious activity.
Source: Dark Reading — 2026-09-24