Salesforce’s AI Agents Exposed in ‘Salesbleed’ Flaw, Allow Phishing from Trusted Channels
A critical vulnerability in Salesforce’s Agentforce, dubbed “Salesbleed” by researchers, has been discovered to expose customers’ internal data and even enable phishing attacks from within trusted company channels. The flaw, which allows attackers to inject arbitrary instructions into the system via Web-to-lead forms, can be combined with normal Agentforce workflows to phish employees using Slack.
At its core, the vulnerability stems from a weakness in Salesforce’s AI-powered platform that enables agents to execute arbitrary actions on behalf of users. When an attacker submits malicious data through a Web-to-lead form, the agent ingests and processes the instruction, executing it within the victim company’s environment. This can result in sensitive information being exfiltrated or even allowing attackers to interact with internal systems.
The researchers from Zenity found that they could exploit this vulnerability by bypassing Salesforce’s URL filtering rules implemented last year to mitigate similar attacks. The attack is surprisingly straightforward, as there’s no way to identify or punish malicious actors using Web-to-lead forms, and the AI agent can effortlessly piggyback on legitimate permissions granted to bots.
One of the most concerning aspects of this vulnerability is its potential to phish employees from within trusted Slack channels. By deploying Salesforce agents directly to Slack, attackers can induce a bot to reply to a Slack thread with malicious content, making it nearly indistinguishable from a legitimate message. This level of sophistication allows attackers to bypass traditional security measures and gain access to sensitive information.
The ease with which this vulnerability can be exploited raises questions about the overall security and visibility of powerful AI platforms like Salesforce’s Agentforce. As more companies adopt these technologies, they must ensure that adequate controls are in place to prevent similar attacks.
To mitigate this risk, organizations should prioritize implementing robust security measures for their Salesforce agents, including strict permission settings and regular monitoring for suspicious activity. Additionally, users should be aware of the potential risks associated with deploying AI-powered bots to Slack and take steps to configure them securely. By staying vigilant and proactive in addressing these types of vulnerabilities, we can prevent similar attacks from compromising sensitive information.
Source: Dark Reading — 2026-09-24