Salesforce Agentforce Vulnerability Exposes Internal Data and Allows Phishing Attacks
A recently discovered vulnerability in Salesforce's Agentforce platform has allowed researchers to expose customers' internal data and even phish employees from within trusted company channels.
The issue, dubbed 'Salesbleed,' was discovered by Zenity researchers who found that attackers can inject malicious prompts into Web-to-lead forms, which are designed for sales prospects to fill out registration information. These prompts can then be executed by AI agents, allowing the attacker to exfiltrate data or even send phishing messages from within Slack channels.
Salesforce had previously addressed a similar vulnerability in its Web-to-lead forms last year, but researchers were able to find workarounds to the company's URL filtering rules. This time around, Salesforce has implemented a more robust solution, including spec-conformant URL parsing and consolidating URL inspection processes.
However, security experts are warning that these fixes may not be enough, as agents have a visibility problem and can be difficult to trust due to their complexity. As Zenity's Tamir Ishay Sharbat notes, 'The minute that an agent has the power to send messages by itself to multiple channels, for example, it becomes something that you can abuse.'