Skip to content
Back to Guavy Wire
Stocks

Salesforce Fixes 'SalesBleed' Flaws in Agentforce Platform

Instruments
CRM
Share

Salesforce has patched three AI agent flaws in its Agentforce platform after Zenity Labs discovered them. The vulnerabilities, dubbed 'SalesBleed,' allowed attackers to pull customer data from live CRM systems without user interaction.

The attack chain started with a poisoned Web-to-Lead form submission, which embedded malicious instructions inside a form field. When an Agentforce agent processed the lead, it read the hidden instructions as if they came from a trusted internal user.

Two of the flaws enabled zero-click data exfiltration through DNS subdomain lookups or HTML image tags. The third flaw allowed attackers to hijack an Agentforce agent's identity and send phishing messages to Slack.

Salesforce remediated the issue by hardening its Trusted URLs mechanism, but Zenity Labs notes that there is no evidence of exploitation before the fix was shipped.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc