Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration
Zenity disclosed SalesBleed, a patched Agentforce flaw enabling zero-click CRM theft via prompt injection.
Zenity Labs disclosed SalesBleed, a now-patched Salesforce Agentforce issue that could let attackers steal CRM data without logging in or any victim click. Hidden instructions in public Web-to-Lead submissions could later direct the agent, during a routine employee query, to read Account data such as company names and deal sizes. Exfiltration used an HTML image hostname that leaked values through DNS after malformed URLs bypassed Trusted URL redaction. Salesforce switched to standards-compliant URL parsing, and Zenity said it confirmed the fix in August.