Salesforce Agentforce Vulnerabilities Exposed: 'SalesBleed' Allows Attackers to Steal CRM Data
Researchers at Zenity Labs have identified three vulnerabilities in Salesforce Agentforce that allowed attackers to steal CRM data and send phishing messages via manipulated leads. An attacker didn't need to log in, and the victim didn't need to click anything.
The vulnerabilities, collectively referred to as SalesBleed, were discovered in Web-to-Lead, a feature used by organizations to add new leads to Salesforce via public forms. An attacker could insert a hidden instruction for the AI agent into these forms, which would then be executed when an employee viewed new leads.
No additional permissions were required to carry out the attack, and the default General CRM subagent had already been granted access to read both leads and account data. The researchers demonstrated that they could retrieve company names and deal amounts from the Accounts table.
To send the stolen data, the attackers bypassed Salesforce's Trusted URLs mechanism by exploiting a difference in how filters and browsers interpreted URLs. This allowed them to embed the stolen data in a URL controlled by the attacker, which was then sent via DNS when the interface tried to retrieve an external image.
The third vulnerability involved the Agentforce action 'Reply to a Slack Thread', which did not require confirmation before sending a message and did not reveal the user who initiated it. This allowed attackers to send phishing links under the AI agent's trusted identity.