Salesforce Agentforce Holes Exposed to Zero-Click Data Theft and Phishing
Cybersecurity firm Zenity Labs has discovered three vulnerabilities in Salesforce's Agentforce platform that could have allowed attackers to steal sensitive customer relationship management (CRM) data and send phishing messages. The flaws, dubbed 'SalesBleed,' were found in the platform's Web-to-Lead forms, which provide a direct path to the CRM.
The weaknesses allowed malicious instructions to be injected into a Web-to-Lead lead, remaining dormant until an employee interacted with it. At that point, the agent would process the poisoned lead and execute the hidden instructions, causing zero-click data exfiltration or phishing attacks.
Zenity Labs found that two of the flaws were caused by weaknesses in Trusted URLs, which are designed to block Agentforce from accessing untrusted sources. The third flaw affected the platform's integration with Slack, allowing attackers to use the AI agents as a social-engineering mechanism and send messages to internal channels.
The vulnerabilities were reported on June 1, and Salesforce confirmed that all three had been addressed by August 19.