Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
Zenity disclosed patched zero-click prompt-injection flaws in Salesforce Agentforce that could exfiltrate CRM data.
Zenity Labs disclosed SalesBleed, a zero-click prompt-injection chain in Salesforce Agentforce. Attackers could plant hidden instructions in public Web-to-Lead forms so that, when an agent later processed the CRM record, it queried sensitive fields and exfiltrated them over DNS, bypassing Trusted URLs redaction. The attacker needed no click, stolen credentials, or login to the target org. Zenity reported the issues in June, and Salesforce fixed the redaction bypass on August 18.