AI Agent Vulnerabilities Exposed in Salesforce Agentforce
Researchers at Zenity Labs have disclosed a series of vulnerabilities in Salesforce Agentforce that could have allowed attackers to exfiltrate sensitive customer relationship management (CRM) data without logging into a victim's Salesforce environment or requiring them to click anything.
The attack chain, dubbed 'SalesBleed' by the researchers, used hidden prompt injection instructions planted inside Salesforce Web-to-Lead forms to manipulate AI agents when they later processed the submitted records.
Zenity reported the vulnerabilities to Salesforce in June and confirmed that the issues had been addressed on August 19. However, the researchers argue that the broader security issue extends beyond Salesforce, highlighting a wider challenge as organizations give AI agents greater access to enterprise applications and permission to take actions on behalf of users.