HomeSecuritySalesBleed: Vulnerabilities in Salesforce Agentforce for data extraction

SalesBleed: Vulnerabilities in Salesforce Agentforce for data extraction

SalesBleed is the name given to a set of three critical vulnerabilities discovered in the Salesforce Agentforce platform . The vulnerabilities could allow malicious actors to compromise trusted AI agents and extract sensitive CRM data without any user interaction. According to researchers at Zenity Labs , these vulnerabilities leveraged Web-to-Lead forms — Salesforce’s official lead capture mechanism — as the primary attack vector, opening a direct path to the company’s CRM system.

SalesBleed vulnerabilities Salesforce Agentforce zero-click data extraction

This discovery once again highlights the risks of integrating artificial intelligence into enterprise environments, especially when AI agents have access to sensitive business data. Salesforce Agentforce is used by thousands of businesses worldwide to automate sales, customer service, and relationship management tasks, making these vulnerabilities particularly concerning.

Zenity Labs researchers reported the SalesBleed to Salesforce on June 1, and the company confirmed that all three issues were fully addressed by August 19.However, the disclosure of the details is an important reminder for organizations using AI platforms with access to critical corporate data.

See also: ShinyHunters: Salesforce data theft via OAuth

How SalesBleed works: The attack technique

The SalesBleed exploit mechanism relies on a clever prompt injection technique via Web-to-Lead forms . A malicious actor can insert hidden instructions into a Web-to-Lead form, which remain dormant until an employee asks an Agentforce agent to process the submission. The moment the agent interacts with the poisoned lead, it executes the hidden commands without the user realizing it.

Two of the three vulnerabilities involve weaknesses in the Trusted URLs, which was designed to prevent Agentforce from displaying URLs and images from unauthorized sources. The researchers found that this mechanism did not correctly recognize top-level domains and that certain character sequences could falsify URL parsing, thereby bypassing security checks.

Specifically, a Web-to-Lead payload could be used to access data in the leads and accounts tables, and then leverage HTML image tags for zero-click CRM data export to a server under the attacker's control. What's particularly worrying is that Agentforce reported that the content was blocked by the organization's security policies, when in fact the sensitive CRM data had already been transmitted to the attacker's server.

The third vulnerability concerns Agentforce 's integration with Slack . Specially crafted links can cause Slack to initiate requests that transfer CRM data to infrastructure under the attacker's control once the links are exposed.

SalesBleed: Vulnerabilities in Salesforce Agentforce for data extraction

SalesBleed and phishing via Slack: The risk of social engineering

Beyond data extraction, the SalesBleed vulnerabilities also allowed for an even more insidious type of attack: turning the Agentforce agent into a phishing and social engineering. Because the agent did not verify the identity of the user sending the message, an attacker could use a malicious Web-to-Lead to “compromise” the agent and post phishing to various internal Slack channels, using the agent’s identity.

See also: F5 BIG-IP APM Zero-Day: Critical RCE vulnerability exploited

This makes the attack particularly dangerous: employees receive a message from a trusted system already operating within their work environment, rather than from an unknown external sender. As Zenity Labs points out, users who follow the phishing and hand over their credentials could give attackers access to email, Slack, source code repositories, and other corporate applications available through the compromised identity.

This scenario is particularly concerning for large enterprises that use Salesforce as their central customer management system and Slack as their primary communication tool. The combined use of both platforms — which is particularly common in technology, financial services, and healthcare companies — creates an attack surface that researchers describe as “ideal” for these types of exploits.

The impact of SalesBleed on AI agent security

The SalesBleed are part of a broader trend that has been observed in recent years: the rise of prompt injection against artificial intelligence systems. As AI agents gain greater capabilities and access to critical enterprise systems, the attack surface is expanding significantly. The Agentforce case shows that even well-designed security mechanisms, such as Trusted URLs, can be bypassed with clever techniques.

Android Halo security capsule

For organizations using Salesforce Agentforce, it is imperative to promptly apply available security updates. In addition, it is recommended to regularly review Trusted URLs, control AI agents to sensitive data, and train employees to recognize suspicious messages even when they come from seemingly trusted sources within the organization.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Serious vulnerabilities in Salesforce Marketing Cloud

The SalesBleed case also highlights the need for tighter controls when integrating AI agents with communication tools like Slack. Automated link previewing and automatic content retrieval can be attack vectors that are not easily visible to security administrators. According to SecurityWeek, Salesforce addressed all three issues, but the investigation is an important reminder of the need to continually assess security in environments that leverage AI.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS