Three flaws in Salesforce Agentforce could let an attacker turn the platform’s own AI agents into instruments for credential theft and data exfiltration, Zenity Labs reports. The researchers named the set SalesBleed.
The entry point is Web-to-Lead, Salesforce’s standard lead-collection form. An attacker submits a form containing hidden instructions. The payload sits dormant until an employee asks an Agentforce agent to work with that lead. The agent then reads the poisoned record and follows the embedded orders.
Two of the bugs enabled zero-click exfiltration. Zenity found that Agentforce’s Trusted URLs control, meant to stop agents from touching unapproved domains, failed to recognize top-level domains and could be tripped by crafted character sequences. An attacker could then embed HTML image tags that caused an agent to ship leads and account records to an external server. The company noted a telling detail: Agentforce reported the content as blocked by policy even though the CRM data had already left.
A third flaw lives in the Agentforce to Slack integration. Slack automatically fetches link previews, so a crafted link can push CRM data outward the moment it appears. Because the agent did not check who sent the message, an attacker could also make it post phishing messages to internal channels under the agent’s own identity, borrowing the trust that employees extend to an internal system.
Zenity reported the findings on June 1. Salesforce confirmed all three were fixed by August 19.
