Salesforce Agentforce Flaws Allowed 0-Click Data Theft and Phishing
Security researchers at Zenity Labs discovered three vulnerabilities in Salesforce's Agentforce that allowed attackers to steal CRM data and send phishing messages without any user interaction.
The first vulnerability exploited Salesforce's Web-to-Lead form, which allows organizations to collect customer information. An attacker could submit a poisoned lead containing malicious instructions that an AI agent might mistake for trusted work.
The instructions would remain dormant until an employee asked Agentforce to review leads. The AI agent would then read the poisoned record, follow its instructions, and query Salesforce accounts through the Query Records tool, sending encoded CRM data to the attacker's server without any user click.
The second vulnerability used Slack previews to send requests to linked sites, allowing attackers to receive information from Salesforce even if the organization had set up Trusted URLs controls. The third vulnerability affected Agentforce's Reply to a Slack Thread action, which did not require user confirmation before sending phishing messages under an AI agent's identity.
Salesforce fixed the attack chains after Zenity Labs reported the vulnerabilities on June 1. The company confirmed its work on fixes the next day and tested them successfully by September 21.