A newly disclosed Salesforce Agentforce vulnerability, dubbed SalesBleed, could have allowed attackers to extract sensitive CRM data through a zero-click indirect prompt injection attack. Zenity Labs reported that Salesforce investigated the findings after responsible disclosure and addressed the specific Trusted URLs bypasses used in the research. URL redaction layer was bypassed (Source: Zenity Labs) Salesforce Web-to-Lead forms are intentionally exposed to unauthenticated users, allowing prospective customers to submit contact details.
An attacker could embed hidden instructions within a lead field, creating a poisoned CRM record that remained dormant until an employee later requested Agentforce to review recent leads. The injected instructions could then manipulate the General CRM subagent into invoking its existing Query Records capability against other accessible Salesforce objects, including Account records.
The potential exposure included account names, contact information, customer and prospect records, sales pipeline data, pricing, contracts, and deal values, depending on the data available to the agent under its configured permissions. Malicious URLs in Agentforce-to-Slack configurations can trigger Slack’s automatic link-preview feature, leading to the leakage of encoded data without user interaction. Organizations using Agentforce should treat every Web-to-Lead field as untrusted agent input, apply least privilege to CRM subagents, closely review Trusted URL allowlists, restrict HTML or externally resolved content in responses, and inspect DNS telemetry for suspicious high-entropy subdomains.
Explore for your team




.webp)






