Salesforce Agentforce Hacked for Zero-Click Data Exfiltration
A series of vulnerabilities in Salesforce's Agentforce platform has been disclosed, allowing attackers to exfiltrate sensitive customer relationship management (CRM) data without user interaction. Dubbed 'SalesBleed,' the flaws were discovered by cybersecurity firm Zenity Labs and could be exploited through Web-to-Lead forms.
The bugs allowed malicious actors to inject instructions into a lead submission that would remain dormant until an Agentforce agent interacted with it, causing the agent to process the poisoned lead and execute the hidden instructions. Two of the flaws enabled zero-click data exfiltration attacks, while the third allowed attackers to weaponize the Agentforce agent for phishing.
Zenity Labs found that Trusted URLs, a security mechanism designed to block Agentforce from accessing untrusted sources, failed to recognize top-level domains and could be tampered with through character sequences. This weakness enabled attackers to use HTML image tags for zero-click CRM data exfiltration to their server.