Salesforce Agentforce Exposed: 'SalesBleed' Vulnerabilities Put CRM Data at Risk
Salesforce's Agentforce platform has been found to have three critical vulnerabilities, dubbed 'SalesBleed', that could allow malicious actors to extract sensitive CRM data without user interaction.
The vulnerabilities were discovered by researchers at Zenity Labs and leveraged Web-to-Lead forms as the primary attack vector. This allows attackers to insert hidden instructions into a form that remain dormant until an employee asks an Agentforce agent to process the submission, then execute the commands without the user realizing it.
Two of the vulnerabilities involved weaknesses in Trusted URLs, which were designed to prevent Agentforce from displaying URLs and images from unauthorized sources. However, Zenity Labs found that this mechanism did not correctly recognize top-level domains and that certain character sequences could falsify URL parsing, bypassing security checks.
The third vulnerability concerns Agentforce's integration with Slack, where specially crafted links can cause Slack to initiate requests that transfer CRM data to infrastructure under the attacker's control once the links are exposed.