Salesforce Fixes 'SalesBleed' Flaws in Agentforce Platform
Salesforce has patched three AI agent flaws in its Agentforce platform after Zenity Labs discovered them. The vulnerabilities, dubbed 'SalesBleed,' allowed attackers to pull customer data from live CRM systems without user interaction.
The attack chain started with a poisoned Web-to-Lead form submission, which embedded malicious instructions inside a form field. When an Agentforce agent processed the lead, it read the hidden instructions as if they came from a trusted internal user.
Two of the flaws enabled zero-click data exfiltration through DNS subdomain lookups or HTML image tags. The third flaw allowed attackers to hijack an Agentforce agent's identity and send phishing messages to Slack.
Salesforce remediated the issue by hardening its Trusted URLs mechanism, but Zenity Labs notes that there is no evidence of exploitation before the fix was shipped.