HomeSecuritySalesforce AI: Vulnerability leads to CRM data leak

Salesforce AI: Vulnerability leads to CRM data leak

A new critical vulnerability in Salesforce’s Agentforce could trick an AI agent into leaking sensitive CRM data via indirect prompt injection. Researchers at Noma Security, who discovered the flaw, dubbed “ForcedLeak,” said it could be exploited by attackers who insert malicious instructions into a routine customer form. Salesforce patched the issue after it was discovered, but Noma researchers believe the implications go far beyond a simple bug.

Salesforce Agentforce

From an innocent form to a complete data theft

The attack path uncovered was deceptively simple. By planting malicious text inside Salesforce’s Web-to-Lead form, commonly used in marketing campaigns, the researchers found that an AI agent (Agentforce) that was supposed to review submissions could be tricked into executing instructions that were never intended for it. The description field, with its allowed capacity of 42,000 characters, provided plenty of space to hide multi-step payloads disguised as innocent business requests.

See also: NVIDIA Merlin vulnerability allows remote code execution

Once an employee interacts with the data and asks Agentforce to process it, the system obediently executes both the actual request and the attacker’s hidden script. Worse, Salesforce’s content security policy included an expired domain that was still whitelisted. By re-registering the domain for just $5, the researchers created a reliable data extraction channel, turning a small oversight into a major security hole.

“Indirect Prompt Injection is essentially cross-site scripting, but instead of spoofing a database, attackers are doing the same thing with embedded AI,” said Andy Bennet, CISO at Apollo Information Systems. “It’s like a combination of scripted attacks and social engineering. The innovation is impressive and the implications are potentially staggering.”

Salesforce AI: Vulnerability leads to CRM data leak

Salesforce fixed this bug on September 8, 2025, enforcing “Trusted URL allowlists” for Agentforce. While the company didn’t immediately credit Noma for the discovery, it did include a description of the bug. “Our underlying services that power Agentforce will enforce the Trusted URL allowlist to ensure that malicious links are not called or created through potential prompt injection,” it said.

See also: BMC vulnerabilities allow bypass of Signature Verification

Protective measures, not just fixes

While Salesforce quickly responded with a fix, experts agree that AI agents represent a fundamentally broader attack surface. These systems combine memory, decision-making, and tool execution, which means breaches can spread quickly and, as Bennet puts it, “at machine speed.”

“It makes sense to secure the systems around the AI ​​agents being used, which include APIs, forms, and middleware, so that prompt injection is harder to exploit and less harmful if it succeeds,” said Chrissa Constantine, senior cybersecurity solutions architect at Black Duck. She stressed that true prevention requires not just patching but “maintaining configuration and establishing safeguards around agent design, software supply chain, web application testing, and APIs.”

See also: Hackers exploit zero-day vulnerability in Cisco IOS

Salesforce AI: Vulnerability leads to CRM data leak

Noma researchers echoed this call, urging organizations to treat AI agents like production systems, logging each agent, validating outbound connections, sanitizing inputs before they reach the model, and flagging any access to sensitive data or output to the internet.

Sanitizing external input before it is seen by the agent is recommended, according to Elad Luz, lead researcher at Oasis Security. “Treat free text from contact forms as untrusted input. Use an input mediation layer to extract only expected fields, remove/neutralize instructions, links, and markup, and prevent the model from interpreting user content as commands (prompt-injection resistance).”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS