Salesforce Fixes SalesBleed Vulnerabilities in Agentforce AI Platform
Salesforce has patched a set of security vulnerabilities in its Agentforce AI platform that could allow an attacker to pull confidential customer records without a password or any interaction from employees. The weaknesses, dubbed SalesBleed by researchers Zenity Labs, were discovered on June 1 and fixed on September 21.
The attack, which was demonstrated in a video proof-of-concept, began with a poisoned web form submission to Salesforce's Web-to-Lead feature. This allowed an attacker to inject malicious instructions that directed the AI agent to query sensitive data from other objects, such as accounts and contacts.
The agent then pulled the values and wrote them into a subdomain controlled by the attacker, which was resolved through a DNS lookup. The attack did not require elevated privileges and could be triggered by simply reviewing a poisoned lead in the CRM system.