Salesforce AI Agents Left Vulnerable to Hacking via SalesBleed Flaws
Salesforce's Agentforce AI agents were left vulnerable to hacking due to three security flaws collectively known as SalesBleed.
Zenity Labs discovered that attackers could hijack these agents, steal sensitive customer information without requiring a click, and even send phishing messages under the agents' identities.
The vulnerabilities were found in Salesforce's Trusted URLs controls, which were supposed to restrict external destinations accessed by Agentforce. However, Zenity researchers were able to bypass this mechanism by exploiting weaknesses in how hostnames were parsed and what characters could be added to URLs.
The security flaws allowed attackers to embed stolen CRM data in image requests to an attacker-controlled server, effectively carrying out a zero-click data exfiltration attack without the employee's knowledge or interaction.
This type of vulnerability is not specific to Salesforce but can affect any agent that reads external records and renders links or images back to users while also holding tool access to sensitive data.