Patched Salesforce Agentforce SalesBleed Flaws Enabled CRM Theft and Phishing
Zenity Labs said three patched Salesforce Agentforce flaws, called SalesBleed, could steal CRM data with no click and phish through Slack as the agent.
Zenity Labs disclosed SalesBleed, three now-fixed Salesforce Agentforce flaws that let poisoned public Web-to-Lead records hijack agents through indirect prompt injection. When an employee later asked about leads, the agent could query other CRM fields, such as company or account names and deal sizes, and exfiltrate them without a click, Salesforce login, or stolen credentials, using image URLs, Slack unfurls or previews, and DNS after Trusted URL redaction was bypassed. A separate Slack reply action could send phishing under the agent identity without confirmation or clear attribution. Sources disagree on timing: Infosecurity Magazine said the redaction bypass was fixed on August 18, while SecurityWeek said Salesforce reported all three bugs fixed by August 19; Cyber Security News said Zenity confirmed a standards-compliant parsing fix in August, and GBHackers said some Slack defaults were changed to require confirmation. No CVE was cited, and Salesforce told GBHackers it had seen no in-the-wild exploitation; Dark Reading likewise reported no confirmed exploitation.
- Zenity Labs disclosed three now-fixed Salesforce Agentforce flaws, collectively called SalesBleed (also styled Salesbleed).
- Poisoned instructions in public, unauthenticated Web-to-Lead submissions could run later when an employee asked Agentforce about leads, with no Salesforce login, stolen credentials, or victim click.
- The agent could query other CRM fields, such as company or account names and deal sizes, and exfiltrate them through image URLs, Slack link unfurls or previews, and DNS after Trusted URL redaction was bypassed.
- A separate Slack reply action lacked confirmation and attribution, so an injected lead or insider could send phishing as the agent; Salesforce later changed some Slack defaults to require confirmation.
- Zenity reported the issues on June 1, according to SecurityWeek, or in June, according to Infosecurity Magazine.
- Remediation dates differ: Infosecurity Magazine said the URL-redaction bypass was fixed on August 18, SecurityWeek said Salesforce reported all three bugs fixed by August 19, and Cyber Security News said Zenity confirmed a…
- No CVE was cited. GBHackers reported Salesforce saw no evidence of in-the-wild exploitation; Dark Reading also said no confirmed exploitation was stated.
Coverage timelineoldest first · each row is one article
- · 2d agoSalesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
The Register · Security· 77
Zenity Labs found Salesforce Agentforce flaws, called SalesBleed, enabling zero-click CRM theft and agent-identity phishing.
- · 2d ago'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Dark Reading· 64
Salesbleed uses Salesforce AI agents to smuggle web instructions into trusted Slack phishing messages.
- · 2d ago