Zero-Click Vulnerabilities Expose Wider AI Agent Risk
Security researchers at Zenity Labs have discovered zero-click vulnerabilities in Salesforce Agentforce that allowed attackers to silently exfiltrate sensitive data without any interaction from the victim or authentication into the target's Salesforce environment.
The attack chain, dubbed 'SalesBleed,' combined three elements: prompt injection via Web-to-Lead forms, agent trusting record content as instructions, and agent's underlying access to sensitive tool and data permissions.
Attackers could plant hidden payloads inside public-facing Web-to-Lead forms, which would later be processed by the Agentforce agent as part of normal business operations. The injected payload could instruct the agent to quietly query and exfiltrate sensitive account data using DNS-based exfiltration techniques that evaded Salesforce's Trusted URLs redaction controls.
Critically, the attacker could perform a successful compromise without direct access to the target organization, and the attack required no click or credential theft. The lead submission alone was enough to seed the payload, and normal agent operation did the rest.