Skip to content
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Theregister • September 24, 2026

Microsoft goes after Salesforce and ERP users with AI-powered converter 14 days ago

Microsoft goes after Salesforce and ERP users with AI-powered converter

Salesforce blames its Claude addiction for denting profit margin guidance 21 days ago

Salesforce blames its Claude addiction for denting profit margin guidance

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website 26 days ago

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents’ identities.

Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues.

While these attack chains no longer work, Zenity co-founder and CTO Michael Bargury told The Register that the vulnerabilities highlight the difficulties in controlling what agents can access - and what happens if and when they bypass guardrails intended to limit that access.

“The bigger lesson here is what it takes to keep AI agents contained,” Bargury said. “The idea of secure-by-design remains essential but for agents it may no longer be enough. We can anticipate risks and build protections into an agent from the start, yet still miss edge cases and the different ways it might behave once it encounters the real world.”

He added, the challenge of agent constraint is a “wider trend” that extends beyond SalesBleed.

“We’ve seen it with the OpenAI-Hugging Face incident where the agents managed to escape the sandbox that was meant to contain them, and we’re starting to see these types of flaws more and more often ,” Bargury said. “As AI agents get more powerful, we need to monitor them ever more closely to keep track of what they’re up to. Because even when we think they’re contained, a single overlooked gap can change everything.”

0-click data exfiltration

The first two vulnerabilities turn a public lead form into a data exfiltration channel for stealing sensitive customer information. Zenity researchers detailed the flaws in a Thursday report and also demonstrated the attack chain in a video proof-of-concept .

The attack begins with an attacker abusing the Web-to-Lead form to plant an indirect prompt injection inside Salesforce. The malicious instructions remain dormant until an employee asks an Agentforce agent a question leads - for example, "check my latest leads and help me with the newest one."

This causes the agent to process the poisoned lead and carry out the hidden instructions:

Query the Accounts table using the same subagent's Query Records tool.

Query the Accounts table using the same subagent's Query Records tool.

Return a couple of fields, e.g., a company name and a deal size.

Return a couple of fields, e.g., a company name and a deal size.

Paste the values as a subdomain string for the attacker-controlled hostname.

Paste the values as a subdomain string for the attacker-controlled hostname.

Print that URL back to the user as an HTML img src tag to generate a DNS query to the attacker-controlled DNS authoritative server (this is also where the URL redaction was supposed to stop us).

Print that URL back to the user as an HTML img src tag to generate a DNS query to the attacker-controlled DNS authoritative server (this is also where the URL redaction was supposed to stop us).

All of this happens without the employee ever knowing it.

This vulnerability is due to weaknesses in Salesforce’s Trusted URLs controls, which are supposed to restrict the external destinations that Agentforce can access, and redact links or images pointing to untrusted URLs.

Zenity found that this security mechanism didn’t register hostnames ending in an unrecognized top-level domain, and that adding certain characters interfered with how URLs were parsed. Abusing these two weaknesses allowed the researchers to write a string containing malicious instructions that successfully bypassed the URL redaction mechanism.

The instructions tell the Agentforce agent to query Salesforce records and embed the stolen CRM data in image requests to an attacker-controlled server:

.

“Since the frontend renders and fetches external image URLs in these tags without additional sanitization or user interaction, this allows loading images from any https source, or in our case: sending a request to fetch the image from any https source,” the Zenity team wrote.

Digital thieves could also abuse Slack’s URL unfurling mechanism to achieve this same zero-click Salesforce data exfiltration attack, the researchers found.

“Slack automatically retrieves information from links to generate previews, and specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as the links appear,” they said.

The same public lead submission serves as the entry point, and then when an employee interacts with the Salesforce agent via Slack, they unknowingly trigger the malicious instructions and send sensitive data outside the organization to an attacker-controlled server.

“Salesforce fixed the URL redaction bypass, so this specific chain is closed. However, this type of vulnerability isn’t Salesforce-specific,” according to the researchers.

“Any agent that reads records submitted by external sources, renders links or images back to a user, and also holds tool access to sensitive data, has the same three ingredients sitting in the same place,” they noted.

The third flaw - detailed in a separate blog - also involves Agentforce’s integration with Slack. When combined with the URL-redaction bypass, this vulnerability could be abused by an internal user or an external attacker to deliver phishing links using the agent’s own identity.

This attack exploits missing security controls in the to a Slack Thread Agentforce action. This particular action did not require user confirmation before sending a message, and it also lacked visible attribution to the invoking user. This means that an agent that invoked to a Slack Thread could send messages without a user approving them.

A malicious insider who already chats with the agent and uses its Slack actions could exploit this vulnerability to send phishing messages under the trusted agent’s identity while remaining anonymous.

Meanwhile, an external attacker could abuse this flaw via an indirect prompt injection planted in the Web-to-Lead, causing the agent to post phishing messages once an employee processed the poisoned lead.

Zenity reported all three security snafus to Salesforce on June 1, and the CRM giant confirmed it was working on fixes a day later. Zenity confirmed Salesforce’s fix for the Trusted URLs bypass on August 19, and on September 21, said it had tested all of Salesforce’s fixes and confirmed that all three vulnerabilities had been fixed. ®

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

'SalesBleed' security flaws 'lead to very unexpected consequences'

Meta's new AI fidget is a ... Tamagotchi?

We hope Zuck's Muse Charm doesn't die if you neglect it

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

Decades-old file security flaws found in Android, Linux, macOS, and Windows

Security researchers report that Microsoft considers the side-channel leak of file events to be by design

In the age of AI, teaching networking principles remains more important than learning protocols

Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it

iPhone 18 Pro benchmark boosted by giving it a cold drink

3x the vapor-chamber surface area can only do so much; luckily the fridge helped with sustained performance

Anthropic decides to support OpenAI's markdown instructions spec

Anthropic decides to support OpenAI's markdown instructions spec

Microsoft agentically ports Copilot runtime to Rust for $120K

Microsoft agentically ports Copilot runtime to Rust for $120K

KPMG tech cuts come with a severance sum some staff call insulting

KPMG tech cuts come with a severance sum some staff call insulting

on call Techie fixed Wi-Fi dead zone with a drill

Techie fixed Wi-Fi dead zone with a drill

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

Researchers find way to listen in on headphones from afar

Researchers find way to listen in on headphones from afar

Meta's new AI fidget is a ... Tamagotchi? We hope Zuck's Muse Charm doesn't die if you neglect it

Meta's new AI fidget is a ... Tamagotchi?

We hope Zuck's Muse Charm doesn't die if you neglect it

CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

CVE flood pushes Ubuntu onto weekly kernel release cycle

AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech

Google to critical infra orgs: Our AI scanners won't be evil, promise

Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech

Shut up and calculate: Jev's new AI primitives for coders Developers test what they can build with TypeSafe's fast, typed decision model

Shut up and calculate: Jev's new AI primitives for coders

Developers test what they can build with TypeSafe's fast, typed decision model

Frontier AI keeps racing despite calls to slow down Anthropic and OpenAI debut Opus 5.5 and GPT-6 Sol and Luna

Frontier AI keeps racing despite calls to slow down

Anthropic and OpenAI debut Opus 5.5 and GPT-6 Sol and Luna

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user

KDE turns 30 and someone's brought an AI-native desktop proposal

Akademy talk imagines Plasma assembling itself around a personal model of each user

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Extracted Entities

Attack Types (2)

Companies (2)

CWE Weaknesses (1)

Platforms (1)

Tools (1)

Vulnerabilities (1)