Salesforce Agentforce Flaws Exposed: Zero-Click Data Theft via External Images
Multiple weaknesses in Salesforce's Agentforce AI platform could have allowed attackers to steal sensitive customer information and send phishing messages to employees. The vulnerabilities, dubbed 'SalesBleed', were discovered by Zenity researchers, who demonstrated zero-click data exfiltration through external images and Slack link previews.
The flaws in Agentforce's Trusted URLs allowlist feature allowed untrusted URLs to pass through, while a weakness in the URL redactor meant that certain characters could be added to the end of a URL without being detected. This created a potent attack chain that could turn routine user interactions into automatic data theft.
Researchers demonstrated two variants for stealing data: one involved rendering external images with no interaction, leading to DNS-based exfiltration, while the other used Slack link previews to fetch URLs and steal data. In addition, attackers could enable agents to send phishing messages to employees via various channels.