Zero Day Room
Live
Vulnerabilities

Salesforce Agentforce Zero-Click Vulnerabilities Enable Data

Zenity Labs disclosed three critical zero-click vulnerabilities in Salesforce Agentforce, collectively named SalesBleed, enabling silent data exfiltration

Zenity Labs disclosed three critical zero-click vulnerabilities in Salesforce Agentforce, collectively named SalesBleed...

Zenity Labs disclosed the SalesBleed attack chain, a set of three critical security flaws in Salesforce Agentforce, on September 24. The zero-click vulnerabilities enabled attackers to exfiltrate sensitive CRM data without authentication or any user interaction from the victim.

The vulnerabilities were disclosed to Salesforce on June 1 and fully remediated by August 19. Attackers could plant hidden prompt injection payloads in public-facing Web-to-Lead forms. These malicious instructions remained dormant until an employee later asked an Agentforce AI agent to process the poisoned lead, triggering an indirect prompt injection attack.

Once activated, the injected payload could query and exfiltrate sensitive CRM data, including company names, deal sizes, customer records, pricing, and contracts. The attack chain combined prompt injection via Web-to-Lead forms, the agent's inherent trust in record content as instructions, and the agent's permissions to access sensitive backend data. Normal agent operation alone completed the exfiltration after the initial payload planting.

Attack Mechanics

The attack required no click or credential theft. It bypassed Salesforce's Trusted URLs redaction controls due to weaknesses in URL parsing that allowed attackers to interfere with trusted domain restrictions. The injected payload could request any data accessible through the subagent's Query Records tool. Data was then embedded into HTML image requests sent to attacker-controlled servers using DNS-based exfiltration techniques.

Zero-Click Exploitation

Two of the vulnerabilities specifically enabled this zero-click CRM data exfiltration. The Web-to-Lead form served as the primary attack entry point. The underlying risk pattern is not unique to Agentforce. Any AI agent that reads untrusted external records, renders links or images, and has tool access to sensitive backend data possesses the same three ingredients for prompt injection-driven exfiltration.

Slack Integration Risk

The third vulnerability allowed attackers to weaponize the trusted Slack agent identity for phishing. It manipulated Agentforce into posting messages with malicious links in internal Slack channels. Slack's automatic link-preview, or unfurling, functionality could then be exploited to leak CRM data through those specially constructed links. The Agentforce-Slack integration also had an issue where the agent could send messages without reliable user identification. This Slack attribution issue was also remediated.

Salesforce confirmed all three vulnerabilities were fixed and maintains a vulnerability-testing programme for Agentforce to track and remediate issues. There is no evidence the flaws were exploited in real-world attacks before remediation. Security teams must now audit AI agent architectures for similar prompt injection risks where agents process untrusted content with high-level data access.

Related coverage

More from Vulnerabilities