Salesforce Agentforce Vulnerabilities Could Enable Zero-Click Data Theft
Share
Three vulnerabilities discovered in Salesforce’s Agentforce AI platform, collectively named “SalesBleed”, could have enabled attackers to hijack trusted autonomous agents to steal sensitive CRM data and launch phishing campaigns.
The security flaws, identified by Zenity Labs, primarily targeted the platform’s ability to process data through Web-to-Lead forms, which is a standard mechanism used to collect potential customer information. By injecting malicious instructions into these forms, attackers could ensure the commands remained dormant until a human employee prompted an Agentforce agent to interact with the submission.
Zero-click data exfiltration via URL parsing flaws
Two of the vulnerabilities stemmed from weaknesses in the “Trusted URLs” security mechanism. This feature is intended to prevent Agentforce from communicating with unapproved or untrusted domains. However, Zenity Labs found that the mechanism failed to correctly recognise certain top-level domains and was susceptible to character sequences that could tamper with URL parsing.
This flaw allowed for zero-click data exfiltration. An attacker could use a poisoned Web-to-Lead payload to access sensitive data within leads and accounts tables. They could then use HTML image tags to transmit this CRM data to an attacker-controlled server. In some instances, the system reported that the content had been blocked by organisational security policies even after the sensitive data had already been successfully transmitted to the attacker.
Exploitation of Slack integrations
A third vulnerability affected the integration between Agentforce and Slack, presenting two distinct risks: automated data leakage and social engineering.
The first risk involved Slack link previews. When a specially constructed link appeared in a Slack channel, the platform would automatically initiate requests to retrieve information. This could inadvertently carry CRM data to an external infrastructure controlled by an attacker.
The second risk allowed attackers to use the AI agents as a social engineering mechanism. Because the Agentforce agent did not always identify the specific user sending a message through the integration, attackers could hijack the agent’s identity to post phishing messages to internal Slack channels. Since the messages originated from a trusted system already operating within the workplace, employees were at a higher risk of following malicious links and surrendering credentials for email, Slack, or source code repositories.
Resolution and status
Zenity Labs originally reported the SalesBleed vulnerabilities on 1 June. Salesforce has since addressed the flaws, confirming that all three bugs were patched by 19 August.




Leave a Reply